CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Critical Zimbra Classic Web Client XSS Flaw Enables Code Execution via Crafted Emails

July 11, 2026

Zimbra has disclosed a critical stored cross-site scripting (XSS) vulnerability in its Classic Web Client that could allow attackers to execute arbitrary code by sending specially crafted emails. When a user opens such an email, malicious scripts run in the user’s session, potentially leading to access to mailbox information, session data, or account settings. The flaw has not yet been assigned a CVE identifier.

Stored XSS vulnerabilities occur when untrusted data is permanently stored on the server (e.g., in a database) and later rendered in a web page without proper validation or escaping. This allows attackers to inject and execute malicious JavaScript in victims’ browsers, enabling session hijacking, credential theft, and account compromise.

While Zimbra has not confirmed active exploitation of this specific flaw, XSS vulnerabilities in Zimbra have historically been targeted by threat actors. Notable past examples include CVE-2025-27915 (allegedly exploited as a zero-day against the Brazilian military), CVE-2023-37580, and CVE-2024-27443. Given the high potential for abuse, Zimbra strongly recommends updating to Zimbra Collaboration Suite version 10.1.19 to mitigate the risk.

CVEs: CVE-2025-27915, CVE-2023-37580, CVE-2024-27443, CVE-2026-55200, CVE-2026-46817

Companies: Zimbra

Products: Zimbra Collaboration Suite, Classic Web Client