CRITICAL 9.3 CVE-2026-93641 Published 25 Sept 2026

Zimbra Classic Stored XSS in Share Notifications

Worried this affects your website?

An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Classic recipient clicks Accept Share.

This allows the attacker to access mailbox data and act as the victim.

Reference: CVE-2026-93641 on NVD

← Back to Security News