CRITICAL
9.3 CVE-2026-93642 Published 25 Sept 2026
Zimbra Stored XSS in Share Notification Allows Account Takeover
Worried this affects your website?
Zimbra Modern contains a stored XSS vulnerability in its share notification handling.
An unauthenticated sender can forge a share notification. When a signed-in recipient clicks Accept Share, the malicious script executes.
- Attack requires no authentication for the sender.
- Victim must be signed in to Zimbra Modern and click Accept Share.
- Impact: attacker can access mailbox data and act as the victim.
Reference: CVE-2026-93642 on NVD
← Back to Security News