VulnSea

Zimbra has 4 CVEs on record. 4 were published in the last 90 days. The busiest recent month was September 2026 with 4. The median CVSS is 9.3 (critical), with 4 rated critical. The most common weakness class is CWE-79 (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
9.3
Publish → KEV
—
Last 90 days
4 prev 0

Products

  • Zimbra Collaboration Suite (ZCS) 4
4
Total CVEs
4
Critical
0
CISA KEV
0
Exploited

Zimbra vulnerabilities

CVEs affecting Zimbra, newest first. Open any entry for full detail, references, and exploit status.

4 CVEsRSS

CVE-2026-93642Critical· 9.3
today

An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Modern recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.

An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Modern recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.

▾ MidnightZimbra · Zimbra Collaboration Suite (ZCS)via NVD
CVE-2026-93641Critical· 9.3
today

An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Classic recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.

An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Classic recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.

▾ MidnightZimbra · Zimbra Collaboration Suite (ZCS)via NVD
CVE-2026-93643Critical· 9.8
today

When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase document can abuse unsigned save fields to perform path-traversal writes and execute commands as zimbra.

When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase document can abuse unsigned save fields to perform path-traversal writes and execute commands as zimbra.

▾ MidnightZimbra · Zimbra Collaboration Suite (ZCS)via NVD
CVE-2026-93647Critical· 9.3
today

An unauthenticated calendar sender can place active markup in a COUNTER message's RFC From address

An unauthenticated calendar sender can place active markup in a COUNTER message's RFC From address. Selecting the message in Zimbra Classic triggers stored XSS, allowing the attacker to access mailbox data and act as the victim.

▾ MidnightZimbra · Zimbra Collaboration Suite (ZCS)via NVD
Zimbra vulnerabilities (CVEs) · VulnSea