CRITICAL 9.3 CVE-2026-93642 Published 25 Sept 2026

Zimbra Stored XSS in Share Notification Allows Account Takeover

Worried this affects your website?

Zimbra Modern contains a stored XSS vulnerability in its share notification handling.

An unauthenticated sender can forge a share notification. When a signed-in recipient clicks Accept Share, the malicious script executes.

  • Attack requires no authentication for the sender.
  • Victim must be signed in to Zimbra Modern and click Accept Share.
  • Impact: attacker can access mailbox data and act as the victim.

Reference: CVE-2026-93642 on NVD

← Back to Security News