CRITICAL 9.3 CVE-2026-93647 Published 25 Sept 2026

Zimbra Classic Stored XSS via Calendar Message From Address

Worried this affects your website?

An unauthenticated calendar sender can place active markup in a COUNTER message's RFC From address.

Selecting the message in Zimbra Classic triggers stored XSS, allowing the attacker to access mailbox data and act as the victim.

Reference: CVE-2026-93647 on NVD

← Back to Security News