Update Now: Critical Zimbra Classic Web Client Flaw Could Expose Mailboxes
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-7796 | Unauthenticated SSRF in Synacor Zimbra Collaboration Suite (CVE-2020-7796) CVE-2020-7796 is a server-side request forgery (SSRF, CWE-918) in Synacor Zimbra Collaboration Suite (ZCS) versions before 8.8.15 Patch 7, rated critical at CVSS 9.8 with network reachability and no authentication or privileges required. The flaw is triggered when the WebEx zimlet is installed and zimlet JSP processing is enabled, allowing an unauthenticated remote attacker to make the Zimbra server issue attacker-controlled requests. Successful SSRF can let the attacker reach internal network services from the mail server's position (e.g., internal admin interfaces or other hosts behind the firewall), potentially leading to information disclosure or further compromise, and the CVSS vector indicates high impact to confidentiality, integrity, and availability. Any organization running a vulnerable Zimbra version with the WebEx zimlet present is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-02-17, confirming active exploitation, and it carries a very high EPSS score (84.4%, top percentile) amid a reported coordinated surge in SSRF exploitation activity. Do: Upgrade Zimbra Collaboration Suite to 8.8.15 Patch 7 or later. If patching must be delayed, remove or disable the WebEx zimlet and disable zimlet JSP processing to eliminate the trigger; first check whether the WebEx zimlet is installed, since instances without it are not exposed to this specific flaw. As a KEV entry, federal agencies must apply vendor mitigations per BOD 22-01 (or discontinue use if unavailable), and all operators should review Zimbra logs for unauthenticated requests reaching zimlet JSP endpoints. | 9.8 | 84% | KEV |
| largetens of thousands of internet-exposed Zimbra servers (public internet scans); the exploitable subset with the WebEx zimlet installed is smaller and of unknown… | |
| CVE-2025-66376 | Stored Cross-Site Scripting in Synacor Zimbra Collaboration Suite Classic UI Zimbra Collaboration Suite (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 is vulnerable to stored cross-site scripting through its Classic webmail interface. An attacker sends an HTML e-mail containing a Cascading Style Sheets (CSS) @import directive, and when a recipient opens that message in Classic UI, the injected content executes as script in the victim's browser session. Successful exploitation lets an attacker run arbitrary JavaScript in the Zimbra webmail context, potentially hijacking the session, reading mail, or acting as the user, consistent with the cross-scope impact reflected in the 6.1 CVSS score. Only deployments running the affected ZCS 10/10.1 versions with the Classic UI enabled are exposed; organizations on patched releases or not using Classic UI are not impacted. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-03-18, confirming exploitation in the wild, and recent reporting describes Zimbra flaws being used by Russian-aligned espionage actors against Western and Ukrainian targets. Do: Upgrade ZCS to 10.0.18 or 10.1.13 (or later) following vendor instructions, as required by CISA's BOD 22-01 KEV guidance; federal agencies and critical infrastructure should prioritize this by the catalog deadline. Until patched, filter or sanitize HTML mail containing CSS @import directives and consider restricting or disabling the Classic UI. Check mailboxes and webmail access logs for suspicious HTML messages and unexplained session activity, which may indicate exploitation. | 6.1 | 20% | KEV |
| largetens of thousands of internet-exposed Zimbra servers (public internet scans typically surface on the order of 50,000+ Zimbra instances), affecting an estimated… | |
| CVE-2025-68645 | PHP Remote File Inclusion in Synacor Zimbra Collaboration Suite (ZCS) Synacor Zimbra Collaboration Suite (ZCS) contains a PHP remote file inclusion (RFI) flaw (CWE-98) reachable through its /h/rest endpoint. By sending crafted requests to /h/rest, a remote attacker can influence the application's internal request dispatching and cause the server to include arbitrary files from the WebRoot directory, potentially exposing sensitive file content or executing attacker-influenced file content reachable there. An attacker who abuses this flaw may gain information disclosure or further compromise of the ZCS server; the available data does not specify authentication requirements or confirm full remote code execution. Any organization running Zimbra Collaboration Suite, especially internet-facing ZCS email and collaboration servers, is potentially affected, though specific affected version ranges were not provided in the available data. The flaw was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2026-01-22, indicating confirmed exploitation in the wild, and EPSS assigns a 49.4% probability of exploitation within 30 days (99th percentile); no public proof-of-concept is known. Do: Apply the patched ZCS release per Synacor's/Zimbra's advisory (specific patched versions were not provided in the available data) and follow CISA KEV required actions, including applicable BOD 22-01 guidance for federal agencies. Review access logs for crafted or anomalous requests to /h/rest and restrict internet exposure of ZCS endpoints until the patch is deployed. Ransomware association is unknown, so treat exploitation activity as potentially preparatory to broader compromise. | 8.8 | 49% | KEV |
| largetens of thousands of internet-exposed ZCS servers (order of ~50,000) |
Full article437 words · extracted from securityaffairs.com · click to collapse

Zimbra addressed a critical stored XSS vulnerability in its Classic Web Client that lets malicious emails execute code when opened.
Zimbra has released version 10.1.19 to fix a critical stored XSS vulnerability in its Classic Web Client, which is widely used to access Zimbra Collaboration. The flaw, which has not yet received a CVE ID, can be exploited by sending specially crafted emails that execute malicious code when opened in the Classic UI. Successful exploitation could allow attackers to access to mailbox information, session data, or account settings.
“The update fixes a security issue in the Classic Web Client where a specially crafted email could run malicious code when the email is opened. If exploited, it could allow access to mailbox information, session data, or account settings.” reads the advisory
“We strongly recommend all customers to upgrade to ZCS v10.1.19 to ensure they have received the latest security patches, bug fixes, and enhancements.”
Google’s Threat Analysis Group discovered the vulnerability.
Although there is no evidence of active exploitation yet, organizations using the Classic Web Client should update as soon as possible.
Since the beginning of 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added [1, 2, 3] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog:
- CVE-2025-68645 (CVSS score of 8.8) Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability
- CVE-2020-7796 (CVSS score of 9.8) Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability
- CVE-2025-66376 (CVSS score of 7.2) Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability.
In March, Russia-linked APT group, likely APT28 (aka UAC-0001, aka Fancy Bear, Pawn Storm, Sofacy Group, Sednit, BlueDelta, and STRONTIUM), exploited the vulnerability CVE-2025-66376 in attacks against entities in Ukraine. Attackers used JavaScript in phishing emails to silently harvest credentials, session tokens, 2FA codes, saved passwords, and 90 days of mailbox data. Then they exfiltrated stolen data via DNS and HTTPS.
A national maritime agency was targeted on January 22 using a compromised student email. Seqrite Labs tracked this campaign as Operation GhostMail.
A phishing email targeted Ukraine’s State Hydrology Agency, part of critical infrastructure, using a compromised student account to appear legitimate. The message hid malicious JavaScript in the HTML body, exploiting a Zimbra XSS flaw (CVE-2025-66376).
Once opened, it executed in the user’s session, stealing credentials, tokens, emails, and 2FA data. The multi-stage payload used SOAP requests, DNS and HTTPS exfiltration, and enabled persistent access, allowing attackers to monitor accounts and extract up to 90 days of emails.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, XSS)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/195130/hacking/update-now-critical-zimbra-classic-web-client-flaw-could-expose-mailboxes.html