SPOJENO AI EPSS 0.01 (nejvyšší)
Critical vulnerabilities in Zimbra Collaboration Suite
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8, CVEs: CVE-2026-93642, CVE-2026-93643, CVE-2026-93647, Summary: CVE-2026-93642 (CVSS: 9.3): An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Modern recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim. CVE-2026-93643 (CVSS: 9.8): When OnlyOffice/Document Editing is available, an unauthenticated remote…
Zimbra FI CA
CVE v události 3
| CVE | hodnocení | KEV | EPSS |
|---|---|---|---|
| CVE-2026-93642 | 9.3 3.1 · rapid7 | – | 0.00 |
| CVE-2026-93643 | 9.8 3.1 · rapid7 | – | 0.01 |
| CVE-2026-93647 | 9.3 3.1 · rapid7 | – | 0.00 |
Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 9.8.
Jak se o tom psalo 2
-
· NCSC-FI FI nadpis události
Critical vulnerabilities in Zimbra Collaboration Suite
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8, CVEs: CVE-2026-93642, CVE-2026-93643, CVE-2026-93647, Summary: CVE-2026-93642 (CVSS: 9.3): An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Modern recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim. CVE-2026-93643 (CVSS: 9.8): When OnlyOffice/Document Editing is available, an unauthenticated remote…
-
· Cyber Centre Kanada CA
Zimbra security advisory (AV26-964)
Serial Number: AV26-964Date: September 25, 2026 As of September 25, 2026, Zimbra is affected by vulnerabilities in the following product: Zimbra Collaboration Suite (ZCS) (Daffodil) Prior to 10.1.21 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. What’s New in Zimbra 10.1.21 (Daffodil) Zimbra Blog - All Things Zimbra