Zimbra 10.1.19 Fixes Stored XSS Flaw Triggered by Crafted Emails
Zimbra has released version 10.1.19 of its Collaboration Suite (ZCS), codenamed “Daffodil,” addressing a stored cross-site scripting (XSS) vulnerability in the Classic Web Client. The patc

Zimbra has released version 10.1.19 of its Collaboration Suite (ZCS), codenamed “Daffodil,” addressing a stored cross-site scripting (XSS) vulnerability in the Classic Web Client. The patch, released on July 7, 2026, closes a flaw that allowed attackers to execute malicious scripts within a victim’s active session simply by sending a specially crafted email. The stored […] The post Zimbra 10.1.19 Fixes Stored XSS Flaw Triggered by Crafted Emails appeared first on Cyber Security News.
Zimbra has released version 10.1.19 of its Collaboration Suite (ZCS), codenamed “Daffodil,” addressing a stored cross-site scripting (XSS) vulnerability in the Classic Web Client. The patch, released on July 7, 2026, closes a flaw that allowed attackers to execute malicious scripts within a victim’s active session simply by sending a specially crafted email. The stored XSS vulnerability resides in how the Classic Web Client renders email content. By embedding malicious script within a crafted email, an attacker could trigger code execution the moment a victim opens or views the message, without requiring any additional user interaction. Critical Stored XSS Flaw Because the payload is “stored,” it persists within the mailbox and can execute repeatedly whenever the email is accessed, expanding the attack window. Stored XSS flaws in webmail clients are particularly dangerous because they operate within an already-authenticated session. Successful exploitation could allow attackers to hijack session cookies, perform actions on the victim’s behalf, exfiltrate sensitive data, or pivot to further compromise the mail environment. Zimbra has not disclosed a CVE identifier or CVSS score for this issue in the current advisory. Affected Packages The fix is delivered through updates to the following components: zimbra-patch→10.1.19.1783177840-2 zimbra-mbox-webclient-war→10.1.19.1783175257-1 Zimbra’s advisory includes specific instructions depending on the version an organization is upgrading from. Customers already running ZCS 10.1.x require no additional action, since existing SNMP mitigations remain effective after upgrading. However, customers migrating from ZCS 10.0.x, 9.0.x, or 8.8.15 must update and reapply the SNMP mitigation once the upgrade to 10.1.19 is complete. Administrators can follow Zimbra’s official installation guide for deploying the July 7, 2026 patch. Zimbra also maintains an open-source repository for those who wish to review or build from source via the zm-build GitHub project. Webmail platforms remain a high-value target for attackers due to the sensitive data and session privileges they handle. Stored XSS vulnerabilities in particular can be weaponized for phishing follow-up campaigns, credential theft, or lateral movement within enterprise networks. Given Zimbra’s widespread use across enterprises and government agencies, security teams should prioritize applying this patch and verifying the status of SNMP mitigation without delay. Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google. The post Zimbra 10.1.19 Fixes Stored XSS Flaw Triggered by Crafted Emails appeared first on Cyber Security News.
Join the Discussion
Comments coming soon. Follow us on social media for real-time discussions.


