Zimbra has urged customers to upgrade to Zimbra Collaboration 10.1.19 to remediate a critical stored cross-site scripting flaw in the Classic Web Client. The vulnerability, which does not yet have a CVE identifier, can be triggered through a specially crafted email and may execute malicious code when a user opens the message in the Classic UI. Successful exploitation could expose session data, account settings, and mailbox contents, creating a direct path to account compromise and data theft.
The issue was reported by Google Threat Analysis Group, and Zimbra said it has no evidence of active exploitation so far. The warning has drawn added attention because Zimbra products have been repeatedly targeted in recent years by Russian state-linked groups including Winter Vivern, APT29, and APT28, while other Zimbra flaws have also appeared in CISA KEV and been used in campaigns against government, military, and Ukrainian entities.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Zimbra warned customers to apply the fix for the critical stored XSS flaw in the Classic Web Client. The company highlighted that opening a crafted email in the Classic UI could execute malicious code and expose mailbox contents and account data.
Zimbra released version 10.1.19 to remediate the critical stored XSS vulnerability affecting the Classic Web Client. The company said the issue had no CVE identifier yet and that there was no confirmed evidence of active exploitation.
Google's Threat Analysis Group reported a critical stored cross-site scripting vulnerability in Zimbra Collaboration Suite's Classic Web Client to Zimbra. The flaw can be triggered through specially crafted emails and could expose session data, account settings, and mailbox contents.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
securityweek.com
Open sourcecysecurity.news
Open sourcethehackernews.com
Open sourcescworld.com
Open sourcesecurityaffairs.com
Open sourcebleepingcomputer.com
Open sourceblog.zimbra.com
Open sourcewiki.zimbra.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.