The weak point is the authenticated mail session, not the gateway. In Zimbra’s Classic Web Client, opening a specially crafted message can run attacker-controlled code inside the user’s browser session, which puts mailbox content, session data, and account settings within reach.
Zimbra says version 10.1.19 fixes the issue, and the flaw is tracked as CVE-2025-27915. The concern is that standard email filtering does not remove the risk once the message lands, because the trigger is the user opening it in the web client.
For teams still running the Classic Web Client, the practical question is exposure to a mail-view XSS that works inside trusted sessions. That makes patch status the key control, especially in higher-sensitivity environments where mailbox access is the real target.