Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4501 articles · 223839 vulns · 37/41 feeds (7d)
← Back to list
9.3
CVE-2026-93641PATCHED
zimbra · zimbra collaboration suite (zcs)

Zimbra Collaboration Suite Classic Web Client Stored Cross-Site Scripting via Forged Share Invitation

Description

An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Classic recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.

Affected Products

VendorProductVersions
zimbrazimbra collaboration suite (zcs)0

References

  • https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories(vendor-advisory)

Related News (1 articles)

Tier C
VulDB2d ago
CVE-2026-93641 | Zimbra Collaboration Suite up to 10.1.20 Share Notification cross site scripting
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.19.3 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
10.1.21
CWECWE-79
PublishedSep 25, 2026
Trending Score24
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-93643
Zimbra Collaboration Suite OnlyOffice Integration Path Traversal Leading to Remote Code Execution via Unauthenticated /downloadas Request
Trending: 32
CRITICALCVE-2026-93647
Zimbra Collaboration Suite Classic Web Client Stored Cross-Site Scripting via Crafted Calendar COUNTER Message From Address
Trending: 24
CRITICALCVE-2026-93642
Zimbra Collaboration Suite Modern Web Client Stored Cross-Site Scripting via Forged Share Invitation
Trending: 24
LOWCVE-2026-73574
CVE-2026-73574: In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Clie
MEDIUMCVE-2026-73572
CVE-2026-73572: In Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scripting (XSS) vulnerability exists in the Zimbra Cla

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 25, 2026
Discovered by ZDM
Sep 25, 2026
Patch Available
Sep 25, 2026