PatchSiren

Zimbra CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Zimbra CVE published 2026-09-25

CVE-2026-93647

An unauthenticated calendar sender can place active markup in a COUNTER message's RFC From address. Selecting the message in Zimbra Classic triggers stored XSS, allowing the attacker to access mailbox data and act as the victim. This vulnerability affects Zimbra Classic deployments, potentially leading to access to sensitive mailbox data and actions as the victim. Defenders should prioritize verification [truncated]

CRITICAL Zimbra CVE published 2026-09-25

CVE-2026-93643

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-25T14:17:23.550Z and has not been modified since then. CVE-2026-93643 allows unauthenticated remote attackers to abuse unsigned save fields in OnlyOffice/Document Editing, leading to path-traversal writes and command execution as zimbra. This vulnerability affects Zimbra installations with publicly [truncated]

CRITICAL Zimbra CVE published 2026-09-25

CVE-2026-93642

An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Modern recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim. This critical vulnerability enables attackers to access mailbox data and act as victims, necessitating prompt verification and mitigation. Defenders should prioritize verifying and mitigating this [truncated]

CRITICAL Zimbra CVE published 2026-09-25

CVE-2026-93641

CVE-2026-93641 is a critical vulnerability in Zimbra Classic that allows an unauthenticated sender to forge a share notification, triggering stored XSS when a signed-in recipient clicks Accept Share. This enables the attacker to access mailbox data and act as the victim. The vulnerability affects Zimbra Classic deployments, and defenders should assess exposure and implement compensating controls to preven [truncated]

Known exploited Zimbra CVE published 2026-08-21

CVE-2026-73570

A high-severity OS command injection vulnerability exists in Synacor Zimbra Collaboration Suite (ZCS). This vulnerability allows an attacker to execute arbitrary commands on the system, potentially leading to elevated privileges or unauthorized access. System administrators and security teams managing ZCS instances should assess exposure and apply mitigations or patches as needed, following CISA's BOD 26- [truncated]

MEDIUM Zimbra CVE published 2026-08-13

CVE-2026-73576

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T16:19:06.923Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. The CVE-2026-73576 record describes a weak cryptographic key generation vulnerability in the OnlyOffice integration of Zimbra Collaboration (ZCS) before 10.1.17. The zimbraDocumentEditingJwtSecret is [truncated]

LOW Zimbra CVE published 2026-08-13

CVE-2026-73575

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T16:19:06.767Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. The CVE-2026-73575 vulnerability exists in the Exchange Web Services (EWS) endpoint of Zimbra Collaboration (ZCS) before version 10.1.17. The vulnerability is caused by insufficient validation of req [truncated]

LOW Zimbra CVE published 2026-08-13

CVE-2026-73574

The CVE-2026-73574 record indicates a local file inclusion (LFI) vulnerability in Zimbra Collaboration before version 10.1.17. The vulnerability exists in the Zimbra Classic Web Client due to improper validation of the 'fu' request parameter. An unauthenticated attacker could exploit this by supplying a crafted path, potentially allowing unauthorized disclosure of protected files within the web applicatio [truncated]

LOW Zimbra CVE published 2026-08-13

CVE-2026-73573

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T16:19:06.437Z and has not been modified since then. The vulnerability affects Zimbra Collaboration (ZCS) before 10.1.17, specifically in the Zimbra Briefcase document editing functionality, allowing authenticated attackers to potentially disclose sensitive files via a path traversal sequence. Org [truncated]

MEDIUM Zimbra CVE published 2026-08-13

CVE-2026-73572

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T16:19:06.287Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. CVE-2026-73572 is a stored cross-site scripting (XSS) vulnerability in Zimbra Collaboration (ZCS) before 10.1.17. The vulnerability exists in the Zimbra Classic Web Client due to insufficient sanitiz [truncated]

LOW Zimbra CVE published 2026-08-13

CVE-2026-73571

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T16:19:06.150Z and has not been modified since then. An authorization bypass vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.17 due to improper authorization validation in delegated email sending functionality. An authenticated attacker can send specially crafted SOAP requests to im [truncated]