Zimbra's security team has urged users of the Classic Web Client to apply an urgent update fixing a critical stored XSS vulnerability. Exploitation could allow attackers to steal session data and mailbox contents via specially crafted emails.
Key Takeaways
- Zimbra released version 10.1.19 to patch a severe XSS flaw.
- All Classic Web Client users must upgrade immediately.
- Russian‑state backed groups have previously exploited similar Zimbra vulnerabilities.
The Zimbra Collaboration Suite (ZCS) powers millions of email users worldwide, including thousands of enterprises and numerous government agencies. Its Classic UI, an Ajax‑driven webmail interface, is prized for speed compared to the newer client but has long carried a hidden security risk.
New Vulnerability and Immediate Patch
On July 10, 2026, Zimbra rolled out ZCS v10.1.19, which addresses a stored cross‑site scripting (XSS) flaw in the Classic Web Client. Although the vulnerability has not yet been assigned a CVE identifier, security researchers warn that a maliciously crafted email can trigger arbitrary code execution when opened, potentially exposing session cookies, account settings, and entire mailboxes.
Historical Exploits and Threat Landscape
State‑sponsored Russian hacking groups have repeatedly targeted Zimbra. In February 2023, the Winter Vivern group leveraged a reflected XSS bug to breach Zimbra portals, stealing emails from NATO‑aligned entities. By October 2024, U.S. and U.K. cyber agencies reported that APT‑29 (Midnight Blizzard/Cozy Bear) was conducting mass‑scale attacks on vulnerable Zimbra servers, reusing a previously abused flaw to harvest credentials. More recently, in March 2025, the Cybersecurity and Infrastructure Security Agency (CISA) mandated federal agencies to patch another Zimbra XSS issue (CVE‑2025‑66376) linked to APT‑28 (Russia’s GRU).
Ongoing Exposure and Recommendations
Shadowserver’s April report highlighted that over 10,500 Zimbra Collaboration Suite instances remain publicly exposed, still susceptible to XSS attacks such as CVE‑2025‑48700. Organizations must therefore adopt a layered defense: timely patch deployment, continuous vulnerability scanning, and real‑time threat intelligence integration.
Actionable Steps
Any customer still operating the Classic Web Client should upgrade to ZCS v10.1.19 without delay. This not only neutralizes the current XSS risk but also reinforces the overall security posture against future exploit attempts.