Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-37580 | Stored Cross-Site Scripting (XSS) in Synacor Zimbra Collaboration Suite (ZCS) CVE-2023-37580 is a cross-site scripting flaw (CWE-79) in Synacor Zimbra Collaboration Suite's webmail interface, publicly described as a stored XSS in which attacker-supplied content persists and executes in victims' browsers. An attacker delivers crafted content (typically a malicious email or message) that, when viewed by a user in the Zimbra webmail client, runs attacker-controlled JavaScript within that user's authenticated session. Successful execution impacts the confidentiality and integrity of the victim's mailbox: the attacker can steal session cookies or credentials, read or alter mail, and act as the user. Any organization running a vulnerable ZCS release is affected, including self-hosted on-premises deployments and providers hosting Zimbra webmail for customers. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2023-07-27, confirming exploitation in the wild (ransomware association unknown), while no public proof-of-concept is posted, CVSS is not yet scored, and EPSS assigns a 46.7% probability of exploitation within 30 days (99th percentile). Do: Apply the latest ZCS patch release addressing CVE-2023-37580 per the Synacor/Zimbra security advisory, as CISA's required action directs, or discontinue use of the affected deployment if mitigation is unavailable; because the flaw is on the KEV list, prioritize internet-facing webmail servers. While patching is pending, restrict webmail exposure (VPN or IP allowlisting) and review webmail and mail-delivery logs for signs of exploitation. Confirm the installed ZCS version and applied patch level against the vendor advisory, since this dataset does not list fixed version numbers. | 6.1 | 47% | KEV |
| masstens of thousands of internet-exposed Zimbra servers (order of 10,000–100,000) serving millions of mailboxes in aggregate (estimate) | |
| CVE-2024-27443 | Cross-Site Scripting in Zimbra Collaboration Suite CalendarInvite (Classic Webmail) CVE-2024-27443 is a cross-site scripting vulnerability (CWE-79) in the CalendarInvite feature of the Zimbra webmail classic user interface in Synacor Zimbra Collaboration Suite (ZCS). It is triggered when a user's browser renders an email containing a crafted calendar header, causing attacker-controlled JavaScript to execute within the webmail session. Successful exploitation allows an attacker to run arbitrary JavaScript in the victim's browser, enabling session/cookie theft and actions performed as the victim inside webmail; no public proof-of-concept is known and CVSS has not yet been scored. Organizations running ZCS where users access mail through the classic webmail UI are affected (deployments restricted to the modern UI are not impacted), though specific affected version ranges have not been published in the available data. The flaw was added to the CISA KEV catalog on 2025-05-19, confirming exploitation in the wild, and EPSS currently estimates a 23.6% probability of exploitation within 30 days (98th percentile). Do: Update ZCS to the patched release for your branch per Synacor/Zimbra's security advisory (specific fixed version numbers are not included in the available data) and confirm whether the classic webmail UI is enabled for any users. Review webmail access logs for suspicious calendar-invite traffic, and note that federal agencies must apply vendor mitigations per BOD 22-01 guidance or discontinue use of the product if mitigations are unavailable. | 6.1 | 24% | KEV |
| mass≈ mass | |
| CVE-2025-27915 | Stored XSS in Zimbra Collaboration Suite Classic Web Client via Malicious ICS Files CVE-2025-27915 is a stored cross-site scripting (XSS) flaw in the Classic Web Client of Synacor Zimbra Collaboration Suite (ZCS) 9.0, 10.0, and 10.1, caused by insufficient sanitization of HTML content in ICS calendar files. It is triggered when a user views an email message containing a malicious ICS entry, at which point embedded JavaScript executes in the victim's session via an ontoggle event handler inside a tag. A successful attacker can run arbitrary JavaScript in the victim's session and perform unauthorized actions on the account, notably creating email filters that silently redirect messages to attacker-controlled addresses, enabling data exfiltration. Any organization running the affected ZCS versions whose users read mail through the Classic Web Client is exposed, since delivery of a single crafted email can compromise a session. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2025-10-07, and public reporting describes active zero-day attacks, including targeting of the Brazilian military via malicious ICS files. Do: Upgrade affected ZCS 9.0, 10.0, and 10.1 deployments to the latest patched builds per Zimbra's security advisory and apply any vendor-recommended mitigations (federal agencies must act per CISA KEV/BOD 22-01 requirements). Hunt for suspicious ICS-based emails and calendar entries, and review user mail filter rules for unauthorized forwarding or redirection to attacker-controlled addresses. Consider restricting or disabling Classic Web Client access until systems are patched. | 5.4 | 4% | KEV PoC |
| large≈30,000–50,000 internet-exposed Zimbra servers; total deployments including internal-only instances likely higher |
Full article356 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananJul 11, 2026Vulnerability / Email Security
Zimbra is urging customers to apply updates to address a critical security vulnerability impacting the Classic Web Client that could result in arbitrary code execution.
The vulnerability has been described as a case of stored cross-site scripting (XSS) that could allow specially crafted emails to execute malicious scripts in a user's session. It has yet to be assigned a CVE identifier.
"The update fixes a security issue in the Classic Web Client where a specially crafted email could run malicious code when the email is opened," Zimbra said. "If exploited, it could allow access to mailbox information, session data, or account settings."
XSS vulnerabilities occur when an application includes untrusted data in a web page without proper validation or escaping. This allows attackers to inject and execute malicious JavaScript in victims' browsers, which can result in session hijacking, credential theft, and account compromise.
Stored XSS, or persistent XSS, is a type of XSS flaw where the injected script is permanently stored on the target servers in a database in the form of a seemingly harmless comment or a forum post, causing any site visitor to be compromised as soon as the page containing the JavaScript is loaded on their web browser.
Although Zimbra makes no mention of the vulnerability being exploited in the wild, XSS flaws in Zimbra have been an attack magnet for years, with bad actors attempting to weaponize such vulnerabilities as far back as December 2021.
Last October, a stored XSS flaw in the Classic Web Client (CVE-2025-27915, CVSS Score: 5.4) was alleged to have been exploited as a zero-day in attacks targeting the Brazilian military, although Zimbra told The Hacker News at the time that it found no evidence to back it up.
Other XSS flaws that have been exploited by threat actors include CVE-2023-37580 and CVE-2024-27443. Given its high potential for abuse, users are recommended to update to Zimbra Collaboration Suite version 10.1.19 for optimal protection.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/07/critical-zimbra-flaw-could-let-crafted_0483473395.html