Vulnerabilities & Exploits · Web App Attack
Classic Web Client XSS Puts Mail Sessions at Risk The weak point is the authenticated mail session, not the gateway. In Zimbra’s Classic Web Client, opening a specially crafted message can run attacker-controlled code inside the user’s browser session, which puts mailbox content, session data, and account settings within reach.
Zimbra says version 10.1.19 fixes the issue, and the flaw is tracked as CVE-2025-27915 . The concern is that standard email filtering does not remove the risk once the message lands, because the trigger is the user opening it in the web client.
For teams still running the Classic Web Client, the practical question is exposure to a mail-view XSS that works inside trusted sessions. That makes patch status the key control, especially in higher-sensitivity environments where mailbox access is the real target.
3 sources · Jul 13
NVD KEV
Known exploited · CISA KEV
CVSS 7.2 HIGH: zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style… EPSS 12% (96th percentile).
CISA federal remediation date Apr 1 · date passed
NVD KEV
Known exploited · CISA KEV
CVSS 6.1 MEDIUM: an issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. EPSS 2% (75th percentile).
CISA federal remediation date Apr 23 · date passed
Timeline Sources Jul 13 SecurityWeek
Zimbra Patches Critical Code Execution Vulnerability
The flaw results in malicious code embedded in crafted emails being executed when the emails are opened.
original Jul 11 The Hacker News
Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions
Zimbra fixes a critical stored XSS flaw in its Classic Web Client that could let crafted emails run malicious scripts when opened.
original Jul 10 BleepingComputer
Zimbra urges customers to patch critical web client XSS flaw
The Zimbra security team urged customers to patch a critical vulnerability affecting the Classic Web Client used to access the Zimbra Collaboration suite.
original Part of the PlainSec briefing for 2026-07-11
Every edition of this story: Classic Web Client XSS Puts Mail Sessions at Risk
More from today
Vulnerabilities & Exploits · Web App Attack
Classic Web Client XSS Puts Mail Sessions at Risk The weak point is the authenticated mail session, not the gateway. In Zimbra’s Classic Web Client, opening a specially crafted message can run attacker-controlled code inside the user’s browser session, which puts mailbox content, session data, and account settings within reach.
Zimbra says version 10.1.19 fixes the issue, and the flaw is tracked as CVE-2025-27915 . The concern is that standard email filtering does not remove the risk once the message lands, because the trigger is the user opening it in the web client.
For teams still running the Classic Web Client, the practical question is exposure to a mail-view XSS that works inside trusted sessions. That makes patch status the key control, especially in higher-sensitivity environments where mailbox access is the real target.
3 sources · Jul 13
NVD KEV
Known exploited · CISA KEV
CVSS 7.2 HIGH: zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style… EPSS 12% (96th percentile).
CISA federal remediation date Apr 1 · date passed
NVD KEV
Known exploited · CISA KEV
CVSS 6.1 MEDIUM: an issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. EPSS 2% (75th percentile).
CISA federal remediation date Apr 23 · date passed
Timeline Sources Jul 13 SecurityWeek
Zimbra Patches Critical Code Execution Vulnerability
The flaw results in malicious code embedded in crafted emails being executed when the emails are opened.
original Jul 11 The Hacker News
Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions
Zimbra fixes a critical stored XSS flaw in its Classic Web Client that could let crafted emails run malicious scripts when opened.
original Jul 10 BleepingComputer
Zimbra urges customers to patch critical web client XSS flaw
The Zimbra security team urged customers to patch a critical vulnerability affecting the Classic Web Client used to access the Zimbra Collaboration suite.
original Part of the PlainSec briefing for 2026-07-11
Every edition of this story: Classic Web Client XSS Puts Mail Sessions at Risk
More from today