Zimbra Classic Web Client: crafted-email code execution fixed in ZCS 10.1.19, surfaced by NCSC-CH (no CVE, exploitation unknown)
NCSC-CH flags a Zimbra Classic Web Client flaw where opening a crafted email runs script in the webmail session, patch to ZCS 10.1.19
Defender actions
- Identify Zimbra tenants still using the Classic Web Client and upgrade to ZCS ≥ 10.1.19; as an immediate interim step, move users to the Modern Web Client, which is not affected.
- Prioritise internet-facing Zimbra webmail; the flaw is unauthenticated and triggers on message open, so exposure is proportional to who can send mail to affected mailboxes.
Analysis
Zimbra released ZCS 10.1.19 on 2026-07-07 to fix a Classic Web Client issue in which "a specially crafted email could run malicious code when the email is opened," potentially granting access to mailbox information, session data or account settings (Zimbra, 2026-07-07); heise online covered it the same day as a stored cross-site-scripting flaw in the legacy webmail UI (heise online, 2026-07-07). Switzerland's NCSC-CH added the item to its Cyber Security Hub on 2026-07-10, describing it as allowing unauthenticated remote attackers to reach session data, account settings and mailbox contents when a victim opens a malicious email, and explicitly recording the exploitation status as unknown (NCSC-CH / GovCERT.ch, 2026-07-10). Only the Classic Web Client is affected; Zimbra and heise recommend switching users to the Modern Web Client as an interim mitigation.
Cited evidence
The update fixes a security issue in the Classic Web Client where a specially crafted email could run malicious code when the email is opened. If exploited, it could allow access to mailbox information, session data, or account settings.
Current exploitation status: UNKNOWN
Sources3
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.