Zimbra Collaboration Suite
4 known vulnerabilities in Zimbra Collaboration Suite, 4 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-93647 CVSS 9.3 critical An unauthenticated calendar sender can place active markup in a COUNTER message's RFC From address. Selecting the message in Zimbra…
- CVE-2026-93643 CVSS 9.8 critical When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase…
- CVE-2026-93642 CVSS 9.3 critical An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Modern recipient clicks Accept…
- CVE-2026-93641 CVSS 9.3 critical An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Classic recipient clicks Accept…