Malicious JavaScript in HTML emails executed when viewed and harvested credentials, session tokens, backup 2FA codes, browser-stored passwords, and up to 90 days of mailbox data. CISA added the flaw to its Known Exploited Vulnerabilities catalog and Zimbra released fixes in versions 10.1.13 and 10.0.18.
Part of the PlainSec briefing for 2026-03-20