Zimbra warned customers to quickly update its email and collaboration software after finding a critical flaw in the Classic Web Client that can be triggered by opening a malicious email. Zimbra fixed the stored cross-site scripting issue in Zimbra Collaboration Suite version 10.1.19; it has no CVE yet. The bug affects the Classic UI webmail interface and could let attackers steal session data, mailbox contents, or account settings.
Why it matters: Organizations using Zimbra webmail, especially the Classic interface, should treat this as urgent because a single crafted email could put user accounts and messages at risk. Update to 10.1.19 as soon as possible and limit or disable use of the Classic client if patching will take time.
Sergiu Gatlan
2026.07.10
100% relevant
This article establishes a new tracked story because it reports Zimbra's release of version 10.1.19 to fix a newly disclosed critical webmail flaw with no CVE yet, rather than updating any existing tracked Zimbra item.
← Back to all stories