Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-93641: Zimbra Classic web client can steal mailbox data
CVE-2026-93641 · published 3 days ago
Summary
A malicious sender can create a fake share invitation that, when a logged‑in Zimbra Classic user clicks "Accept Share," runs hidden code in the user's browser. This lets the attacker view the user's mailbox contents and act as the user. Apply the latest Zimbra update or patch to stop the forged invitations from being processed.
What to do
- Update zimbra zimbra collaboration suite (zcs) to version 10.1.21 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| zimbra | zimbra collaboration suite (zcs) | < 10.1.21 |
Original advisory text
Zimbra Collaboration Suite Classic Web Client Stored Cross-Site Scripting via Forged Share Invitation
An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Classic recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.
Severity
9.3
Critical
CVSS 3.1: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-79Cross-site Scripting (XSS)
Timeline
Published25 Sep 2026
Updated27 Sep 2026
First seen25 Sep 2026
Track software like this
Free during beta