VULNERABILITY OVERVIEW
A critical stored cross-site scripting (XSS) vulnerability in Zimbra's Classic Web Client allows attackers to send specially crafted emails that execute arbitrary malicious JavaScript in the recipient's browser session when the email is opened, enabling access to mailbox data, session tokens, and account settings. Discovered by Google's Threat Analysis Group; no CVE identifier has been assigned yet as of July 12. No active exploitation reported, but prior Zimbra XSS flaws (CVE-2023-37580, CVE-2024-27443, CVE-2025-66376) have been actively weaponized by APT groups including APT28. Patch to ZCS version 10.1.19 immediately.
CVSS BREAKDOWN
↗
Attack Vector
NETWORK
△
Attack Complexity
LOW
⚷
Privs Required
NONE
◈
User Interaction
REQUIRED
⊕
Scope / Impact
CHANGED
C:H · I:H · A:N
AFFECTED VERSIONS
Zimbra Collaboration Suite Classic Web Client, versions prior to ZCS 10.1.19CITATIONS
- → https://thehackernews.com/2026/07/critical-zimbra-flaw-could-let-crafted_0483473395.html
- → https://securityaffairs.com/195130/hacking/update-now-critical-zimbra-classic-web-client-flaw-could-expose-mailboxes.html
- → https://www.wiu.edu/cybersecuritycenter/cybernews.php