Zimbra Collaboration Suite Classic Web Client Stored XSS (patched in 10.1.19, no CVE yet)

Zimbra Collaboration Suite Classic Web Client Stored XSS (TL-2026-1208) is a critical-severity software vulnerability, first published 2026-07-11. It has no confirmed attribution, affects Zimbra Zimbra Collaboration Suite - Classic Web Client, maps to 13 MITRE ATT&CK techniques (T1027, T1041, T1056), and is covered by 9 detection rules and 20 indicators of compromise.

Key facts for TL-2026-1208

Threat ID
TL-2026-1208
Severity
CRITICAL
Status
PATCHED
Category
VULNERABILITY
First published
2026-07-11
Last reviewed
2026-07-11
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, government administration, military, critical-infrastructure, transport
Target regions
Global
Detection rules
9
Indicators of compromise
20

Malware and tooling in Zimbra Collaboration Suite Classic Web Client Stored XSS

Malware and tooling: Zimbra Classic Web Client XSS credential/session-stealer script, Custom JavaScript webmail credential/session harvester

Zimbra shipped ZCS 10.1.19 on 2026-07-07 to fix a stored cross-site scripting flaw in the Classic Web Client, reported by Google's Threat Analysis Group, where a specially crafted email executes malicious JavaScript when opened, exposing mailbox data, session tokens, and account settings. No CVE has been assigned and Zimbra has not confirmed in-the-wild exploitation, but the Classic Web Client's email-rendering pipeline has been the target of at least five prior state-linked XSS exploitation campaigns since 2023.

How Zimbra Collaboration Suite Classic Web Client Stored XSS works

On 2026-07-07 Zimbra released Zimbra Collaboration Suite (ZCS) 10.1.19, patching a stored cross-site scripting (XSS) vulnerability in the Classic Web Client (zimbra-mbox-webclient-war component). The flaw allows a specially crafted email to execute attacker-controlled JavaScript in the victim's authenticated webmail session the moment the message is opened, with no further user interaction required. Successful exploitation could expose mailbox contents, active session/authentication data, and account configuration settings to the attacker's script.

The issue was reported to Zimbra by Google's Threat Analysis Group (TAG), a unit that specializes in tracking government-backed and commercial surveillance actors targeting high-risk users such as journalists, dissidents, and opposition politicians. Zimbra's public patch notes and release documentation do not disclose the specific injection point, sanitization gap, or a CVE identifier, and Zimbra has not stated the bug is being exploited in the wild.

This disclosure is the sixth publicly documented stored/reflected XSS issue in Zimbra's Classic Web Client email-rendering path since 2023 (following CVE-2023-37580, CVE-2024-27443, CVE-2025-27915, CVE-2025-48700, and CVE-2025-66376), each exploiting a different HTML/CSS/ICS-calendar sanitization gap in the same client, and four of the five prior flaws were confirmed exploited by state-linked actors (Winter Vivern/UNC4907, APT28/Sednit/Forest Blizzard) against government, military, and critical-infrastructure targets, or added to CISA's Known Exploited Vulnerabilities catalog. Given that pattern and the TAG provenance of this report, the vulnerability is tracked as a patch-now priority despite the absence of a confirmed campaign at time of writing.

Remediation is to upgrade to ZCS 10.1.19 or later; organizations still on 10.0.x, 9.0.x, or 8.8.15 must reapply their SNMP mitigations after upgrading.

MITRE ATT&CK techniques used in TL-2026-1208

Defense Evasion

T1027 Obfuscated Files or Information

Exfiltration

T1041 Exfiltration Over C2 Channel

Credential Access

T1056 Input Capture; T1528 Steal Application Access Token; T1539 Steal Web Session Cookie

Execution

T1059 Command and Scripting Interpreter

Command and Control

T1071 Application Layer Protocol

Persistence

T1098 Account Manipulation

Collection

T1114 Email Collection

Initial Access

T1566 Phishing

Resource Development

T1583 Acquire Infrastructure; T1587 Develop Capabilities

Reconnaissance

T1591 Gather Victim Org Information

Affected products and versions in Zimbra Collaboration Suite Classic Web Client Stored XSS

  • Zimbra — Zimbra Collaboration Suite - Classic Web Client
    Vulnerable versions: all versions prior to 10.1.19
    Fixed in: 10.1.19

Remediation for Zimbra Collaboration Suite Classic Web Client Stored XSS

Patches

  • Zimbra Collaboration Suite 10.1.19 (package zimbra-patch 10.1.19.1783177840-2, zimbra-mbox-webclient-war 10.1.19.1783175257-1), released 2026-07-07

Immediate actions

  • Upgrade all Zimbra Collaboration Suite Classic Web Client deployments to 10.1.19 or later
  • If upgrading from ZCS 10.0.x, 9.0.x, or 8.8.15, reapply SNMP mitigations after the upgrade — they are not retained automatically
  • Encourage users to migrate from the Classic Web Client to the Modern Web App where feasible, since the recurring XSS class is specific to the Classic Web Client email-rendering pipeline
  • Advise high-risk users (journalists, dissidents, government/political staff) to treat unsolicited or unexpected emails, calendar invites, and ICS attachments with caution until patched

Workarounds

  • No official workaround published; Zimbra's guidance is to upgrade to 10.1.19

Longer-term hardening

  • Deploy behavioral/EDR-style monitoring for anomalous webmail session activity (mass export, new auto-forward rules, SOAP API abuse)
  • Monitor CISA KEV and Zimbra Security Advisories for a retroactive CVE assignment and any confirmation of in-the-wild exploitation for this specific fix
  • Restrict internet-facing exposure of Zimbra webmail interfaces where possible, given the documented pattern of mass scanning (10,500+ vulnerable ZCS instances found exposed for CVE-2025-48700 in April 2026)
  • Audit mailbox forwarding/filter rules periodically given prior campaigns' use of auto-forwarding for persistence

Weaknesses (CWE) in Zimbra Collaboration Suite Classic Web Client Stored XSS

CWE-79, CWE-80

Timeline of Zimbra Collaboration Suite Classic Web Client Stored XSS

  • First observed in-the-wild exploitation of a Zimbra Classic Web Client stored XSS (CVE-2023-37580) against a government organization in Greece — the earliest of the campaigns establishing this vulnerability class as a nation-state target.
  • Zimbra pushed a hotfix for CVE-2023-37580 to a public GitHub repository ahead of a formal advisory.
  • Zimbra released the official patch for CVE-2023-37580, later attributed in part to Winter Vivern (UNC4907).
  • Zimbra patched CVE-2025-27915 (ZCS 9.0.0 Patch 44, 10.0.13, 10.1.5), an ICS calendar-attachment stored XSS previously exploited against the Brazilian military via spoofed diplomatic ICS files.
  • CVE-2024-27443, a Classic Web Client CalendarInvite header stored XSS linked to APT28/Sednit exploitation (Operation RoundPress), was added to the CISA Known Exploited Vulnerabilities catalog.
  • Zimbra patched CVE-2025-66376, a CSS @import-based stored XSS in the Classic UI, in versions 10.1.13 and 10.0.18.
  • Seqrite Labs disclosed Operation GhostMail: Russia-linked APT28 exploiting CVE-2025-66376 against Ukrainian government and critical-infrastructure targets, including the State Hydrology Agency, to steal credentials, tokens, and up to 90 days of email.
  • Shadowserver reported over 10,500 internet-facing ZCS instances still vulnerable to CVE-2025-48700 exploitation, concentrated in Asia and Europe.
  • Zimbra released ZCS 10.1.19, fixing the newly reported stored XSS in the Classic Web Client (zimbra-mbox-webclient-war).
  • Zimbra published its 10.1.19 patch-release blog post urging all Classic Web Client customers to upgrade as soon as possible.
  • BleepingComputer reported on the flaw, noting Google TAG's involvement signals possible targeting of high-risk individuals such as dissidents and journalists.
  • The Hacker News published coverage of the Zimbra 10.1.19 stored XSS fix, the source article for this threat record.

Sources cited for Zimbra Collaboration Suite Classic Web Client Stored XSS

Threats related to Zimbra Collaboration Suite Classic Web Client Stored XSS

Detection coverage for TL-2026-1208

As of 2026-07-11, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1208 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats