Briefing

Zimbra Urges Customers to Patch Classic Web Client for Critical XSS Vulnerability

security
by [email protected] (The Hacker News) ·

Patch Zimbra Classic Web Client immediately to mitigate XSS that could lead to arbitrary code execution.

What to do now

Patch Zimbra Classic Web Client immediately to mitigate XSS that could lead to arbitrary code execution.

Summary

Zimbra has identified a critical stored cross‑site scripting (XSS) flaw in its Classic Web Client that could allow specially crafted emails to execute malicious scripts within a user’s session, potentially leading to arbitrary code execution. The vulnerability, which has not yet received a CVE identifier, is actively being exploited in the wild. Zimbra is urging all customers to apply the latest security update immediately to mitigate the risk. The flaw resides in the email rendering engine of the Classic Web Client and can be triggered by maliciously crafted messages. The patch addresses the XSS vector by sanitizing input before rendering. Failure to update could expose users to remote code execution. The advisory emphasizes the urgency of applying the fix before attackers leverage the vulnerability. The update is available through the Zimbra admin console and can be deployed across all affected installations.

Key changes

  • Stored XSS in Classic Web Client allows malicious scripts via crafted emails
  • Could lead to arbitrary code execution in user sessions
  • No CVE assigned yet, but actively exploited
  • Zimbra urges customers to apply the latest security update
  • Patch sanitizes input before rendering to block the XSS vector

Affects

enterprise

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting