HomeSecurityZimbra: Critical vulnerability in Classic Web Client requires immediate upgrade

Zimbra: Critical vulnerability in Classic Web Client requires immediate upgrade

Zimbra is urging its customers to immediately upgrade their installations after identifying a critical security vulnerability affecting the Classic Web Client , the well-known web interface for accessing the Zimbra Collaboration suite . According to the company, this particular security flaw can be exploited via specially crafted emails, allowing an attacker to execute malicious code once the victim opens the message.

Zimbra: Critical vulnerability

Zimbra has already released the new version 10.1.19, which fixes the issue, urging all organizations still using the Classic Web Client to proceed with its installation without delay. Although the vulnerability has not yet received an official CVE identifier, its severity is considered particularly high, as it can lead to the interception of sensitive data and accounts email

What is Zimbra Collaboration?

Zimbra Collaboration is one of the most widely used email and corporate collaboration platforms worldwide. It is used by thousands of businesses, universities, organizations and government agencies, serving hundreds of millions of users.

See also: XRING: Serious bug in XQUIC threatens HTTP/3 servers

Although the platform now features a more modern web interface, many organizations continue to use the Classic Web Client. This version is based on Ajax and remains very popular, as it offers faster response and better management of large mailboxes without the increased resource requirements of the newer version.

However, its widespread use means that any serious security breach can affect a large number of organizations around the world.

How the new attack works

The vulnerability belongs to the category of stored Cross-Site Scripting (Stored XSS), one of the most dangerous forms of XSS attacks. Unlike other techniques, the malicious code is stored in the email content itself and is activated when the user opens the message through the Classic Web Client.

In this way, the attacker can execute JavaScript in the victim's browser environment, gaining access to session data, authentication cookies, account information, or even email content.

Once an account is compromised, the attacker can gain access to corporate mail, contacts, calendars, file attachments, and other sensitive information, creating serious risks to both the privacy and security of an organization.

Zimbra: Critical vulnerability in Classic Web Client requires immediate upgrade

Zimbra's recommendation to administrators

The company leaves no room for misinterpretation regarding the seriousness of the situation. In its official announcement, it points out that all organizations using the Classic Web Client should immediately install ZCS version 10.1.19, as the vulnerability exclusively affects this interface.

While there is no public evidence that the vulnerability is already being exploited in real-world attacks, the report came from Threat Analysis Group (TAG) , which has significant experience in detecting zero-day attacks and state-sponsored cyberespionage campaigns, which has increased interest in the vulnerability.

See also: Ill Bloom: Vulnerability allowed $3.1 million to be stolen from crypto wallets

Zimbra is constantly in the crosshairs of cyberspies

The new warning is not an isolated incident. In recent years, Zimbra has repeatedly been at the center of cyber espionage campaigns, mainly due to its widespread use in government organizations and critical infrastructure.

In 2023, the Winter Vivern, which is linked to Russia, exploited a reflected XSS vulnerability to gain access to email accounts of government officials, diplomats, and military personnel associated with NATO.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

A few months later, cybersecurity agencies in the United States and the United Kingdom warned that the APT29 group (Cozy Bear or Midnight Blizzard) was carrying out massive attacks against vulnerable Zimbra installations, exploiting known security vulnerabilities to steal user credentials.

At the same time, in March 2025, the US CISA asked all federal agencies to fix another XSS vulnerability, which was used by the APT28 (Fancy Bear) in attacks against Ukrainian state organizations.

Zimbra: Critical vulnerability in Classic Web Client requires immediate upgrade

Why managers shouldn't procrastinate

The repeated exploitation of Zimbra vulnerabilities proves that email platforms are one of the most important targets of modern cyberattacks. A successful email compromise can be the first step to intercept confidential information, install additional malware , or even completely compromise a corporate network.

The situation is even more worrying when you consider that, according to the Shadowserver organization, more than 10,500 Zimbra servers exposed to the internet were recently vulnerable to other known XSS attacks. This fact shows that many organizations are systematically delaying security updates, creating a wide field of action for cybercriminals and state espionage groups.

See also: Ubiquiti: Critical vulnerability in UniFi OS – Update now

For this reason, immediate installation of the latest version, continuous monitoring of suspicious activity, and implementation of strong security policies are now essential requirements for protecting any infrastructure based on the Zimbra Collaboration suite.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS