Zimbra’s Classic Web Client Hit by Critical XSS Flaw, Patch Urged for Millions of Users
A severe vulnerability has been discovered in Zimbra’s Classic Web Client, a widely used email and collaboration software suite that serves hundreds of millions of people worldwide. The security flaw, which allows attackers to execute malicious code through specially crafted emails, has prompted the company to release an emergency patch. If left unaddressed, this critical web client XSS issue could lead to sensitive information theft, compromising user accounts and mailbox data.
Zimbra’s Classic Web Client is a fast and resource-efficient interface for accessing email folders, but it’s also a potential entry point for threat actors. The recently released ZCS v10.1.19 patch addresses the stored cross-site scripting (XSS) vulnerability, which has yet to receive a CVE ID. Attackers can exploit this flaw by sending malicious emails that execute code when opened, granting them access to user session data, account settings, and mailbox information.
Zimbra’s warning is clear: customers using the Classic Web Client should upgrade to ZCS v10.1.19 as soon as possible to prevent potential attacks. The company’s urgency stems from a history of state-sponsored hacking groups exploiting similar vulnerabilities in their software. Russian state-backed hackers have been linked to several high-profile breaches targeting NATO-aligned organizations and individuals, including government officials and military personnel.
The latest patch comes after a series of warnings from US and UK cyber agencies regarding APT29 (Midnight Blizzard and Cozy Bear) hackers working for Russia’s Foreign Intelligence Service (SVR). These groups have been exploiting Zimbra XSS flaws on a massive scale, stealing email account credentials and compromising sensitive information. The Cybersecurity and Infrastructure Security Agency (CISA) has also ordered federal agencies to patch another Zimbra XSS flaw exploited by APT28 hackers in attacks targeting Ukrainian government entities.
Security teams are reminded that vulnerabilities like this can be detected through regular testing and simulation exercises. By staying vigilant and proactive, organizations can prevent potential breaches before they occur. In light of this latest development, users are advised to test every layer of their environment, including security protocols and tools, to ensure they remain secure against emerging threats.
As cybersecurity threats continue to evolve, it’s essential for organizations to prioritize patch management and regular security assessments to stay ahead of attackers. This critical XSS flaw in Zimbra’s Classic Web Client serves as a stark reminder that even widely used software can harbor vulnerabilities that must be addressed promptly.
Source: Bleeping Computer — 2026-07-10