Zimbra disclosed security updates for Zimbra Collaboration Suite (ZCS) Daffodil releases before 10.1.21, addressing vulnerabilities that include CVE-2026-93643, a critical unauthenticated path-traversal flaw in the OnlyOffice/Document Editing integration. An attacker able to access an existing supported public Briefcase document can abuse unsigned save fields in a /downloadas request to write files through path traversal and execute commands as the zimbra user; the flaw is rated CVSS 9.8. Canadian and Guyanese national cyber authorities urged administrators to review Zimbra’s release information and apply the available update.
Two additional unauthenticated stored XSS vulnerabilities, CVE-2026-93642 and CVE-2026-93647, can let attackers execute script in authenticated users’ browsers and access mailbox data or act as those users. The first uses a forged share invitation accepted in Zimbra Modern, while the second embeds active markup in the From field of a calendar COUNTER message viewed in the Classic client. Rapid7 warned that weaknesses across Zimbra mail, document, and calendar functions can support business email compromise campaigns that manipulate the records employees use for decisions, creating coordinated fraudulent communications and complicating forensic investigation.

See affected versions and whether adversaries are exploiting it.
11 events from the most recent confirmed update back to the earliest known activity.
Zimbra issued a security advisory for Zimbra Collaboration Suite Daffodil versions before 10.1.21, recommending affected users update to version 10.1.21. Canadian and Guyanese cyber authorities echoed the update recommendation; the notices did not identify the underlying CVEs.
Rapid7's CVE team received records for CVE-2026-93642, a Modern Web Client share-invitation XSS; CVE-2026-93647, a Classic calendar COUNTER-message XSS; and CVE-2026-93643, an OnlyOffice integration path-traversal issue that can enable command execution as the zimbra user.
CISA added unauthenticated Zimbra SNMP notification command-injection flaw CVE-2026-73570 to its KEV catalog and gave U.S. federal agencies three days to remediate it.
CISA added CVE-2025-27915, a stored cross-site scripting flaw in the Zimbra Classic Web Client triggered through a crafted ICS calendar attachment, to the Known Exploited Vulnerabilities catalog.
CISA added Zimbra postjournal unauthenticated command-injection vulnerability CVE-2024-45519 to its Known Exploited Vulnerabilities catalog.
Proofpoint observed attackers using Base64-encoded payloads in CC fields during exploitation activity involving Zimbra postjournal command-injection flaw CVE-2024-45519.
Rapid7 tracked widespread exploitation of CVE-2022-27925 and CVE-2022-37042. Attackers could chain the path-traversal and authentication-bypass flaws to install a JSP web shell on Zimbra servers without credentials.
Collaborative Rapid7 and Zimbra research reportedly uncovered more than 50 Zimbra Collaboration Suite vulnerabilities, including issues enabling sender impersonation, inbox-visibility control, and modification of shared documents and calendars.
Shadowserver identified more than 260 compromised Zimbra instances while searching for artifacts associated with exploitation of CVE-2026-73570.
CVE-2025-27915 was reportedly used as a zero-day against Brazilian military targets to steal email and create covert forwarding filters.
Google Threat Analysis Group documented four threat groups exploiting Zimbra zero-day CVE-2023-37580 to target email, credentials, and authentication tokens.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
6 references tracked. Mallory keeps watching after this page renders.
cyber.gc.ca
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcerapid7.com
Open sourcecirt.gy
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.