Vulnerability Management Zimbra urges patching of critical XSS vulnerability in Classic Web Client July 10, 2026 Share By SC Staff (Adobe Stock) Zimbra is urging customers to patch a critical stored cross-site scripting (XSS) vulnerability affecting its Classic Web Client. This flaw allows attackers to execute malicious code by sending specially crafted emails, potentially leading to the theft of session data, account settings, or mailbox information. The company released Zimbra 10.1.19 to address the issue, which was reported by Google's Threat Analysis Group, based on information published by Bleeping Computer. The vulnerability, which currently lacks a CVE ID, impacts the Classic Web Client interface of the Zimbra Collaboration suite, used by millions globally, including businesses and government agencies. Successful exploitation could compromise sensitive user data. Zimbra strongly recommends upgrading to version 10.1.19 to mitigate the risk. While not yet confirmed as exploited in the wild, the reporting by Google's Threat Analysis Group is significant, as they often identify exploits used by state-backed actors. Zimbra products have been a frequent target for Russian state-sponsored hackers, including groups like Winter Vivern and APT29, who have previously exploited similar flaws to steal emails and credentials from government and military organizations. The Cybersecurity and Infrastructure Security Agency (CISA) has issued orders for federal agencies to patch Zimbra vulnerabilities exploited in attacks targeting Ukrainian government entities and has warned of ongoing attacks exploiting other XSS flaws, with thousands of instances remaining vulnerable. Source: Bleeping Computer SC Staff Related Vulnerability Management Researcher finds 9 vulnerabilities in ATM security software SC Staff July 10, 2026 Matt Burch, a principal security researcher at Atredis Partners, will present his findings on CryptoPro Secure Disk at Black Hat USA 2026. Vulnerability Management HP DeskJet 2800 series printers vulnerable to sensitive data exposure SC Staff July 9, 2026 Vulnerability Management Critical Gitea flaw allows authentication bypass via single HTTP header SC Staff July 9, 2026 The vulnerability stems from an insecure default configuration in Gitea's official Docker images (versions prior to 1.26.3) where the "REVERSE_PROXY_TRUSTED_PROXIES" setting is set to "*". Related Events Cybercast Why Mythos is the cybersecurity crisis we need Wed Jul 22 Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Bug Buffer Overflow Disassembly You can skip this ad in 5 seconds