CRITICAL
9.3 CVE-2026-93647 Published 25 Sept 2026
Zimbra Classic Stored XSS via Calendar Message From Address
Worried this affects your website?
An unauthenticated calendar sender can place active markup in a COUNTER message's RFC From address.
Selecting the message in Zimbra Classic triggers stored XSS, allowing the attacker to access mailbox data and act as the victim.
Reference: CVE-2026-93647 on NVD
← Back to Security News