Zimbra Classic Web Client stored XSS security update
Security Patch Release
Summary
Hide ▲
Show ▼
Zimbra released ZCS v10.1.19 to patch a stored XSS flaw in the Classic Web Client, narrowing exposure for users of that interface. The bug could be triggered through specially crafted emails and could expose session data, account settings, or mailbox information if opened. Zimbra told customers to upgrade as soon as possible because the issue affects only Classic Web Client users and had no CVE ID yet.
Related Happenings
Zimbra security patch release for CVE-2026-50055
Security Patch Release
H score14
First: 21.07.2026 16:18
Last: 21.07.2026 16:18
Sources 1
About this happening:
Zimbra 10.1.20 fixes CVE-2026-50055, a mail forwarding restriction bypass affecting Zimbra accounts with forwarding restrictions. The patch closes a flaw that coul...
Zimbra security patch release for CVE-2026-50055
Security Patch ReleaseAbout this happening: Zimbra 10.1.20 fixes CVE-2026-50055, a mail forwarding restriction bypass affecting Zimbra accounts with forwarding restrictions. The patch closes a flaw that coul...
Zimbra SNMP monitoring component command injection
Security Patch Release
H score31
First: 21.07.2026 16:18
Last: 21.07.2026 16:18
Sources 1
About this happening:
Zimbra 10.1.20 patches a command injection flaw in the SNMP monitoring component that could permit command execution when SNMP notifications are enabled. The f...
Zimbra SNMP monitoring component command injection
Security Patch ReleaseAbout this happening: Zimbra 10.1.20 patches a command injection flaw in the SNMP monitoring component that could permit command execution when SNMP notifications are enabled. The f...
Synacor Zimbra CVE-2025-48700 security patch release
Security Patch Release
H score76
First: 24.04.2026 16:35
Last: 24.04.2026 16:35
Sources 1
About this happening:
Synacor released security patches for CVE-2025-48700, fixing an XSS flaw in Zimbra Classic UI that could be triggered by a malicious email and expose sensiti...
Synacor Zimbra CVE-2025-48700 security patch release
Security Patch ReleaseAbout this happening: Synacor released security patches for CVE-2025-48700, fixing an XSS flaw in Zimbra Classic UI that could be triggered by a malicious email and expose sensiti...
APT28 Operation GhostMail Zimbra phishing campaign targeting Ukrainian government entities
Campaign
H score37
First: 19.03.2026 16:55
Last: 19.03.2026 16:55
Sources 1
About this happening:
APT28’s Operation GhostMail is actively targeting Ukrainian government entities through a phishing chain that exploits CVE-2025-66376 in Zimbra Collaboration Sui...
APT28 Operation GhostMail Zimbra phishing campaign targeting Ukrainian government entities
CampaignAbout this happening: APT28’s Operation GhostMail is actively targeting Ukrainian government entities through a phishing chain that exploits CVE-2025-66376 in Zimbra Collaboration Sui...
CISA patch guidance for Zimbra and SharePoint flaws
Advisory/Mitigation
H score56
First: 19.03.2026 08:05
Last: 19.03.2026 08:05
Sources 1
About this happening:
CISA, NSA, and partner agencies issued a joint advisory on CVE-2025-66376, a stored XSS flaw in Zimbra Collaboration Classic UI that lets a crafted email r...
CISA patch guidance for Zimbra and SharePoint flaws
Advisory/MitigationAbout this happening: CISA, NSA, and partner agencies issued a joint advisory on CVE-2025-66376, a stored XSS flaw in Zimbra Collaboration Classic UI that lets a crafted email r...
Timeline
-
10.07.2026 14:47 3 articles · 13d ago
Zimbra releases ZCS v10.1.19 to patch Classic Web Client stored XSS
Mitigation Patch UpdateZimbra released ZCS v10.1.19 to patch a stored cross-site scripting (XSS) flaw in the Classic Web Client used to access the Zimbra Collaboration suite, and told Classic Web Client customers to upgrade as soon as possible. The flaw can be triggered by specially crafted emails opened in the Classic UI and could expose session data, account settings, or mailbox information.
Show sources
- Zimbra urges customers to patch critical web client XSS flaw — www.bleepingcomputer.com — 10.07.2026 14:47
- Zimbra urges customers to patch critical web client XSS flaw — www.bleepingcomputer.com — 10.07.2026 14:47
- Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions — thehackernews.com — 11.07.2026 09:45