CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →
← Back to Daily brief 2026-07-10
NOTABLENATOA2vulnerability

Zimbra Classic Web Client: crafted-email code execution fixed in ZCS 10.1.19, surfaced by NCSC-CH (no CVE, exploitation unknown)

NCSC-CH flags a Zimbra Classic Web Client flaw where opening a crafted email runs script in the webmail session, patch to ZCS 10.1.19

Defender actions

  • Identify Zimbra tenants still using the Classic Web Client and upgrade to ZCS ≥ 10.1.19; as an immediate interim step, move users to the Modern Web Client, which is not affected.
  • Prioritise internet-facing Zimbra webmail; the flaw is unauthenticated and triggers on message open, so exposure is proportional to who can send mail to affected mailboxes.

Analysis

Zimbra released ZCS 10.1.19 on 2026-07-07 to fix a Classic Web Client issue in which "a specially crafted email could run malicious code when the email is opened," potentially granting access to mailbox information, session data or account settings (Zimbra, 2026-07-07); heise online covered it the same day as a stored cross-site-scripting flaw in the legacy webmail UI (heise online, 2026-07-07). Switzerland's NCSC-CH added the item to its Cyber Security Hub on 2026-07-10, describing it as allowing unauthenticated remote attackers to reach session data, account settings and mailbox contents when a victim opens a malicious email, and explicitly recording the exploitation status as unknown (NCSC-CH / GovCERT.ch, 2026-07-10). Only the Classic Web Client is affected; Zimbra and heise recommend switching users to the Modern Web Client as an interim mitigation.

Cited evidence

The update fixes a security issue in the Classic Web Client where a specially crafted email could run malicious code when the email is opened. If exploited, it could allow access to mailbox information, session data, or account settings.

Zimbra 2026-07-07

Current exploitation status: UNKNOWN

NCSC-CH / GovCERT.ch 2026-07-10

Sources3

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.