Update Now: Critical Zimbra Classic Web Client Flaw Could Expose Mailboxes
2026-07-11T02:51:39Z•7de4ddb4d1260e63e2712a44d3ebd0a62a0899a9f519e69a390e96f0ef6d7d7f
criticalpatchstored-xssupdate-nowvulnerabilitywebmailxsszimbrazimbra-classic-web-client
What happened
Zimbra patched a critical stored cross-site scripting (XSS) vulnerability in the Classic Web Client that allows malicious email content to execute code when a message is opened, potentially exposing mailboxes, sessions, or credentials. Zimbra released version 10.1.19 to address the issue; no CVE has been assigned yet. Administrators should apply the update immediately (or disable the Classic Web Client and tighten HTML/email content filtering) to prevent exploitation.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 7de4ddb4d1260e63e2712a44d3ebd0a62a0899a9f519e69a390e96f0ef6d7d7f
- Enrichment time
- 2026-07-11T02:51:39Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.