**Critical Web Client Vulnerability Hits Zimbra Users**
Zimbra, a popular email and collaboration software suite used by hundreds of millions worldwide, is urging its customers to patch a critical vulnerability affecting its Classic Web Client. The flaw, which has yet to receive a CVE ID, allows attackers to steal sensitive information through specially crafted emails that execute malicious code when opened.
The issue lies in the stored cross-site scripting (XSS) security flaw, which can be exploited by threat actors to steal session data, account settings, or mailbox information. Zimbra’s warning is clear: any customer using the Classic Web Client should upgrade to version 10.1.19 as soon as possible to prevent exploitation.
The vulnerability has significant implications, particularly given its potential for widespread exploitation. The fact that Google’s Threat Analysis Group flagged this flaw suggests it may already be in use by state-backed hacking groups targeting high-risk individuals and organizations. This is not an isolated incident; Zimbra security issues have been frequently exploited by Russian state-sponsored hackers in recent years.
One notable example is the Winter Vivern group, which used a reflected XSS exploit to breach Zimbra webmail portals in February 2023, compromising thousands of vulnerable servers. The APT29 hacking group has also targeted Zimbra servers at scale, exploiting flaws previously abused to steal email account credentials. Most recently, CISA ordered federal agencies to patch another Zimbra XSS flaw exploited by hackers linked to the APT28 group.
The fact that so many organizations have been compromised through these vulnerabilities is a stark reminder of the importance of timely patches and regular security updates. It’s essential for users to prioritize their security posture and take immediate action to mitigate this risk.
To protect your organization, it’s crucial to test every layer of your security defenses regularly. This can be achieved through breach and attack simulation tests that validate your SIEM and EDR rules, ensuring threats don’t slip by detection. Don’t wait for attackers to test your defenses – start testing today.
Source: Bleeping Computer — 2026-07-10