Zimbra has disclosed a critical stored cross-site scripting (XSS) vulnerability in its Classic Web Client that could allow attackers to execute arbitrary code by sending specially crafted emails. When a user opens such an email, malicious scripts run in the user’s session, potentially leading to access to mailbox information, session data, or account settings. The flaw has not yet been assigned a CVE identifier.
Stored XSS vulnerabilities occur when untrusted data is permanently stored on the server (e.g., in a database) and later rendered in a web page without proper validation or escaping. This allows attackers to inject and execute malicious JavaScript in victims’ browsers, enabling session hijacking, credential theft, and account compromise.
While Zimbra has not confirmed active exploitation of this specific flaw, XSS vulnerabilities in Zimbra have historically been targeted by threat actors. Notable past examples include CVE-2025-27915 (allegedly exploited as a zero-day against the Brazilian military), CVE-2023-37580, and CVE-2024-27443. Given the high potential for abuse, Zimbra strongly recommends updating to Zimbra Collaboration Suite version 10.1.19 to mitigate the risk.
CVEs: CVE-2025-27915, CVE-2023-37580, CVE-2024-27443, CVE-2026-55200, CVE-2026-46817
Companies: Zimbra
Products: Zimbra Collaboration Suite, Classic Web Client
Original source: thehackernews.com