DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:07:52ZSOURCES: 14CRITICAL: 34
⚠ ACTIVE ALERTS
@AlvieriD CRITICAL — CORRELATED | Actor '888' listing on PwnForums: claims 35GB of Accenture source code,… /// @DarkWebInformer CRITICAL — CORRELATED | Prinz Eugen ransomware operation — actor ROOTBOY (aka avtokz / GERMANIA)… /// @MalwareHunterTeam CRITICAL — CORRELATED | PolinRider (DPRK / Famous Chollima / Contagious Interview) supply chain… /// @GossiTheDog CRITICAL — CORRELATED | CVE-2026-8037 Progress Kemp LoadMaster pre-auth RCE — exploitation attempts… /// @FalconFeedsio CRITICAL — CORRELATED | Tracking '888' forum listing for Accenture data (July 6, 2026). Dataset:…
34Critical Threats
19Active CVEs
10IOCs Tracked
7New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-PENDING-ZIMBRA-2026PUBLISHED: 2026-07-11
HIGHCVE-PENDING-ZIMBRA-2026

Zimbra Collaboration Classic Web Client Critical Stored XSS (No CVE Assigned Yet)

VENDOR: Zimbra (Synacor)//PRODUCT: Zimbra Collaboration Suite — Classic Web Client
8.8
HIGH
CVSS 3.1
PATCH STATUS
PATCH AVAILABLE
EXPLOIT STATUS
NO KNOWN EXPLOIT

A critical stored cross-site scripting (XSS) vulnerability in Zimbra's Classic Web Client allows attackers to send specially crafted emails that execute arbitrary malicious JavaScript in the recipient's browser session when the email is opened, enabling access to mailbox data, session tokens, and account settings. Discovered by Google's Threat Analysis Group; no CVE identifier has been assigned yet as of July 12. No active exploitation reported, but prior Zimbra XSS flaws (CVE-2023-37580, CVE-2024-27443, CVE-2025-66376) have been actively weaponized by APT groups including APT28. Patch to ZCS version 10.1.19 immediately.

Attack Vector
NETWORK
Attack Complexity
LOW
Privs Required
NONE
User Interaction
REQUIRED
Scope / Impact
CHANGED
C:H · I:H · A:N
AFFECTED VERSIONSZimbra Collaboration Suite Classic Web Client, versions prior to ZCS 10.1.19
  • https://thehackernews.com/2026/07/critical-zimbra-flaw-could-let-crafted_0483473395.html
  • https://securityaffairs.com/195130/hacking/update-now-critical-zimbra-classic-web-client-flaw-could-expose-mailboxes.html
  • https://www.wiu.edu/cybersecuritycenter/cybernews.php
SHARE BRIEF:✕ Post on Xin Share on LinkedIn