Zimbra Collaboration Suite Classic Web Client Stored XSS (patched in 10.1.19, no CVE yet)
Zimbra Collaboration Suite Classic Web Client Stored XSS (TL-2026-1208) is a critical-severity software vulnerability, first published 2026-07-11. It has no confirmed attribution, affects Zimbra Zimbra Collaboration Suite - Classic Web Client, maps to 13 MITRE ATT&CK techniques (T1027, T1041, T1056), and is covered by 9 detection rules and 20 indicators of compromise.
Key facts for TL-2026-1208
- Threat ID
- TL-2026-1208
- Severity
- CRITICAL
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- 2026-07-11
- Last reviewed
- 2026-07-11
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, government administration, military, critical-infrastructure, transport
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 20
Malware and tooling in Zimbra Collaboration Suite Classic Web Client Stored XSS
Malware and tooling: Zimbra Classic Web Client XSS credential/session-stealer script, Custom JavaScript webmail credential/session harvester
Zimbra shipped ZCS 10.1.19 on 2026-07-07 to fix a stored cross-site scripting flaw in the Classic Web Client, reported by Google's Threat Analysis Group, where a specially crafted email executes malicious JavaScript when opened, exposing mailbox data, session tokens, and account settings. No CVE has been assigned and Zimbra has not confirmed in-the-wild exploitation, but the Classic Web Client's email-rendering pipeline has been the target of at least five prior state-linked XSS exploitation campaigns since 2023.
How Zimbra Collaboration Suite Classic Web Client Stored XSS works
On 2026-07-07 Zimbra released Zimbra Collaboration Suite (ZCS) 10.1.19, patching a stored cross-site scripting (XSS) vulnerability in the Classic Web Client (zimbra-mbox-webclient-war component). The flaw allows a specially crafted email to execute attacker-controlled JavaScript in the victim's authenticated webmail session the moment the message is opened, with no further user interaction required. Successful exploitation could expose mailbox contents, active session/authentication data, and account configuration settings to the attacker's script.
The issue was reported to Zimbra by Google's Threat Analysis Group (TAG), a unit that specializes in tracking government-backed and commercial surveillance actors targeting high-risk users such as journalists, dissidents, and opposition politicians. Zimbra's public patch notes and release documentation do not disclose the specific injection point, sanitization gap, or a CVE identifier, and Zimbra has not stated the bug is being exploited in the wild.
This disclosure is the sixth publicly documented stored/reflected XSS issue in Zimbra's Classic Web Client email-rendering path since 2023 (following CVE-2023-37580, CVE-2024-27443, CVE-2025-27915, CVE-2025-48700, and CVE-2025-66376), each exploiting a different HTML/CSS/ICS-calendar sanitization gap in the same client, and four of the five prior flaws were confirmed exploited by state-linked actors (Winter Vivern/UNC4907, APT28/Sednit/Forest Blizzard) against government, military, and critical-infrastructure targets, or added to CISA's Known Exploited Vulnerabilities catalog. Given that pattern and the TAG provenance of this report, the vulnerability is tracked as a patch-now priority despite the absence of a confirmed campaign at time of writing.
Remediation is to upgrade to ZCS 10.1.19 or later; organizations still on 10.0.x, 9.0.x, or 8.8.15 must reapply their SNMP mitigations after upgrading.
MITRE ATT&CK techniques used in TL-2026-1208
Defense Evasion
T1027 Obfuscated Files or Information
Exfiltration
T1041 Exfiltration Over C2 Channel
Credential Access
T1056 Input Capture; T1528 Steal Application Access Token; T1539 Steal Web Session Cookie
Execution
T1059 Command and Scripting Interpreter
Command and Control
T1071 Application Layer Protocol
Persistence
Collection
Initial Access
Resource Development
T1583 Acquire Infrastructure; T1587 Develop Capabilities
Reconnaissance
Affected products and versions in Zimbra Collaboration Suite Classic Web Client Stored XSS
- Zimbra — Zimbra Collaboration Suite - Classic Web Client
Vulnerable versions: all versions prior to 10.1.19
Fixed in: 10.1.19
Remediation for Zimbra Collaboration Suite Classic Web Client Stored XSS
Patches
- Zimbra Collaboration Suite 10.1.19 (package zimbra-patch 10.1.19.1783177840-2, zimbra-mbox-webclient-war 10.1.19.1783175257-1), released 2026-07-07
Immediate actions
- Upgrade all Zimbra Collaboration Suite Classic Web Client deployments to 10.1.19 or later
- If upgrading from ZCS 10.0.x, 9.0.x, or 8.8.15, reapply SNMP mitigations after the upgrade — they are not retained automatically
- Encourage users to migrate from the Classic Web Client to the Modern Web App where feasible, since the recurring XSS class is specific to the Classic Web Client email-rendering pipeline
- Advise high-risk users (journalists, dissidents, government/political staff) to treat unsolicited or unexpected emails, calendar invites, and ICS attachments with caution until patched
Workarounds
- No official workaround published; Zimbra's guidance is to upgrade to 10.1.19
Longer-term hardening
- Deploy behavioral/EDR-style monitoring for anomalous webmail session activity (mass export, new auto-forward rules, SOAP API abuse)
- Monitor CISA KEV and Zimbra Security Advisories for a retroactive CVE assignment and any confirmation of in-the-wild exploitation for this specific fix
- Restrict internet-facing exposure of Zimbra webmail interfaces where possible, given the documented pattern of mass scanning (10,500+ vulnerable ZCS instances found exposed for CVE-2025-48700 in April 2026)
- Audit mailbox forwarding/filter rules periodically given prior campaigns' use of auto-forwarding for persistence
Weaknesses (CWE) in Zimbra Collaboration Suite Classic Web Client Stored XSS
CWE-79, CWE-80
Timeline of Zimbra Collaboration Suite Classic Web Client Stored XSS
- First observed in-the-wild exploitation of a Zimbra Classic Web Client stored XSS (CVE-2023-37580) against a government organization in Greece — the earliest of the campaigns establishing this vulnerability class as a nation-state target.
- Zimbra pushed a hotfix for CVE-2023-37580 to a public GitHub repository ahead of a formal advisory.
- Zimbra released the official patch for CVE-2023-37580, later attributed in part to Winter Vivern (UNC4907).
- Zimbra patched CVE-2025-27915 (ZCS 9.0.0 Patch 44, 10.0.13, 10.1.5), an ICS calendar-attachment stored XSS previously exploited against the Brazilian military via spoofed diplomatic ICS files.
- CVE-2024-27443, a Classic Web Client CalendarInvite header stored XSS linked to APT28/Sednit exploitation (Operation RoundPress), was added to the CISA Known Exploited Vulnerabilities catalog.
- Zimbra patched CVE-2025-66376, a CSS @import-based stored XSS in the Classic UI, in versions 10.1.13 and 10.0.18.
- Seqrite Labs disclosed Operation GhostMail: Russia-linked APT28 exploiting CVE-2025-66376 against Ukrainian government and critical-infrastructure targets, including the State Hydrology Agency, to steal credentials, tokens, and up to 90 days of email.
- Shadowserver reported over 10,500 internet-facing ZCS instances still vulnerable to CVE-2025-48700 exploitation, concentrated in Asia and Europe.
- Zimbra released ZCS 10.1.19, fixing the newly reported stored XSS in the Classic Web Client (zimbra-mbox-webclient-war).
- Zimbra published its 10.1.19 patch-release blog post urging all Classic Web Client customers to upgrade as soon as possible.
- BleepingComputer reported on the flaw, noting Google TAG's involvement signals possible targeting of high-risk individuals such as dissidents and journalists.
- The Hacker News published coverage of the Zimbra 10.1.19 stored XSS fix, the source article for this threat record.
Sources cited for Zimbra Collaboration Suite Classic Web Client Stored XSS
- Critical Zimbra Flaw Could Let Crafted Emails Steal Data
- Zimbra 10.1.19 Patch Release Update
- Zimbra Collaboration Suite 10.1.19 Release Notes
- Zimbra urges customers to patch critical web client XSS flaw
- Zimbra 0-day used to target international government organizations
- Russian APT Exploits Zimbra Vulnerability Against Ukraine
- Russian APT targets Ukraine via Zimbra XSS flaw CVE-2025-66376
- Zimbra Zero-Day Exploited to Target Brazilian Military via Malicious ICS Files
- Zimbra Collab XSS Vuln Added to CISA KEV [CVE-2024-27443]
- Over 10,000 Zimbra servers vulnerable to ongoing XSS attacks
Threats related to Zimbra Collaboration Suite Classic Web Client Stored XSS
Detection coverage for TL-2026-1208
As of 2026-07-11, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1208 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.