Update Now: Critical Zimbra Classic Web Client Flaw Could Expose Mailboxes

2026-07-11T02:51:39Z7de4ddb4d1260e63e2712a44d3ebd0a62a0899a9f519e69a390e96f0ef6d7d7f
criticalpatchstored-xssupdate-nowvulnerabilitywebmailxsszimbrazimbra-classic-web-client

What happened

Zimbra patched a critical stored cross-site scripting (XSS) vulnerability in the Classic Web Client that allows malicious email content to execute code when a message is opened, potentially exposing mailboxes, sessions, or credentials. Zimbra released version 10.1.19 to address the issue; no CVE has been assigned yet. Administrators should apply the update immediately (or disable the Classic Web Client and tighten HTML/email content filtering) to prevent exploitation.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
7de4ddb4d1260e63e2712a44d3ebd0a62a0899a9f519e69a390e96f0ef6d7d7f
Enrichment time
2026-07-11T02:51:39Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.