Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions
2026-07-11T13:24:08Z•8753e003d67135c332b0c28041cac698b6756d7e8d942794411e32db6358c946
GHSA-hjr6-g723-hmfmcrypto-exploitdenial-of-servicefirmwarehardware-attackill-bloominjective-labsmodbeaconnpmopenclawprogressratsharefilesilver-foxstorage-zone-controllerstored-xsssupply-chaintangemu-bootwallet-theftwordpresswp-shellstormxquicxringzimbra
What happened
This feed highlights multiple high-impact security incidents and vulnerabilities: a critical stored XSS in Zimbra Classic Web Client that could allow arbitrary script execution in user sessions; Progress advising ShareFile customers to shut down Windows Storage Zone Controllers due to a credible external threat; and an npm package compromise of Injective Labs that pushed wallet-key‑stealing code. Other notable items include six U‑Boot flaws (crash and boot‑time code execution), a Tangem wallet laser password‑reset attack, OpenClaw flaws (GHSA-hjr6-g723-hmfm) enabling host compromise, the new g
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 8753e003d67135c332b0c28041cac698b6756d7e8d942794411e32db6358c946
- Enrichment time
- 2026-07-11T13:24:08Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.