Critical vulnerabilities in Zimbra Collaboration Suite
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8, CVEs: CVE-2026-93642, CVE-2026-93643, CVE-2026-93647, Summary: CVE-2026-93642 (CVSS: 9.3): An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Modern recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim. CVE-2026-93643 (CVSS: 9.8): When OnlyOffice/Document Editing is available, an unauthenticated remote…
EPSS 0.01 CVSS 9.8 CVE-2026-93642 CVE-2026-93643 CVE-2026-93647 Zimbra FI