← All stories
● Covered by 5 sources · 12 reportsMedium impact7 negative

Zimbra Releases Critical Security Patches for Classic Web Client

🔄 Updated 70d ago — new reporting from The Record, BleepingComputer, The Hacker News, Ars Technica
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Zimbra patched critical XSS flaw in Classic Web Client.
  • The update is available as Zimbra version 10.1.19.
  • Version 10.1.20 fixes multiple vulnerabilities including command injection.
  • Zimbra urges prompt updates to secure systems.
  • The XSS flaw has yet to receive a CVE ID.
  • The Classic UI is an Ajax-based webmail interface.
  • Zimbra 10.1.19 was released on Tuesday, July 7.
  • Zimbra Collaboration Suite (ZCS) is a communication software solution.
  • Zimbra 10.1.20 patches nine security vulnerabilities.
  • The command injection impacts the SNMP monitoring component.
  • Zimbra 10.1.20 fixes four XSS defects in the Classic Web Client.
  • Zimbra 10.1.20 resolves CVE-2026-50055, a mail forwarding restriction bypass.
  • Zimbra 10.1.20 resolves CVE-2026-10631, an access control vulnerability.
  • Zimbra 10.1.20 resolves CVE-2026-50054, an authorization issue.
  • Russian state-sponsored hacking group Laundry Bear exploits the Zimbra flaw.
  • Laundry Bear is also known as Void Blizzard.
  • Laundry Bear targets organizations in the Defense Industrial Base, government, and education.
  • The exploited flaw is CVE-2025-66376, an XSS vulnerability.
  • Laundry Bear exploited the flaw as a zero-day before November 2025.
  • CISA tagged the vulnerability as actively exploited.
  • International agencies issued an alert regarding Laundry Bear's attacks.
  • Laundry Bear previously targeted Ukrainian entities.
  • Zimbra is used by hundreds of millions of people, thousands of businesses, and hundreds of government agencies.
  • The Classic UI is faster than Zimbra's modern web client.
  • Exploitation of the XSS flaw could steal session data, account settings, or mailbox information.
  • The command injection impacts the SNMP monitoring component if SNMP notifications are enabled and Swatchdog is running.
  • Zimbra 10.1.20 fixes a server-side request forgery (SSRF) bug.
  • Zimbra 10.1.20 fixes an XSS vulnerability where malicious attachment filenames execute script.
  • Zimbra 10.1.20 fixes an XSS vulnerability where crafted fields execute script.
  • Zimbra 10.1.20 fixes an XSS vulnerability where crafted attachments execute script.
  • Jonah Burgess of Rapid7 discovered the mail forwarding restriction bypass.
  • Laundry Bear targets organizations in energy, law enforcement, media, NGOs, and technology.
  • The exploited flaw allows JavaScript in HTML emails to execute automatically when viewed.
  • Laundry Bear's exploit steals account data without requiring a click or visit to a phishing site.
  • International agencies from the U.S., U.K., Europe, Australia, and New Zealand issued the alert.
  • Laundry Bear's campaign targets U.S. and NATO organizations.
  • The campaign indicates espionage activities with Russian government backing.
  • The Russian group exploited the zero-day for at least five months in 2025.
  • The payload steals the last 90 days of email, the entire email directory, browser-saved passwords, and 2FA recovery codes.
  • The NSA and Proofpoint also published research on the campaign.
  • The XSS vulnerability abuses CSS @import handling to execute JavaScript.

Critical XSS Vulnerability

Zimbra has addressed a critical stored cross-site scripting (XSS) vulnerability affecting its Classic Web Client, used globally by businesses and government agencies. This vulnerability lets attackers execute malicious code with specially crafted emails. Zimbra users are urged to upgrade to version 10.1.19 to mitigate this risk.

Wide-Ranging Security Updates

Beyond the critical XSS vulnerability, Zimbra has rolled out additional security updates in version 10.1.20. These patches cover nine vulnerabilities, including a serious command injection flaw in the SNMP monitoring component, which could allow unauthenticated users to execute OS commands remotely.

These updates also address four other XSS flaws in the Classic Web Client, security loopholes in email forwarding, and access control issues, significantly bolstering security for users of the platform.

User Action Required

Zimbra's updates emphasize the necessity for prompt user action to prevent potential exploits. The broad user base of Zimbra's email and collaboration suite underscores the importance of securing installations against these vulnerabilities to avoid data compromises.

Updates

🕒 2026-07-23 · new reporting from The Hacker News
  • Zimbra is used by hundreds of millions of people, thousands of businesses, and hundreds of government agencies.
  • The Classic UI is faster than Zimbra's modern web client.
  • Exploitation of the XSS flaw could steal session data, account settings, or mailbox information.
  • The command injection impacts the SNMP monitoring component if SNMP notifications are enabled and Swatchdog is running.
  • Zimbra 10.1.20 fixes a server-side request forgery (SSRF) bug.
  • Zimbra 10.1.20 fixes an XSS vulnerability where malicious attachment filenames execute script.
  • Zimbra 10.1.20 fixes an XSS vulnerability where crafted fields execute script.
  • Zimbra 10.1.20 fixes an XSS vulnerability where crafted attachments execute script.
  • Jonah Burgess of Rapid7 discovered the mail forwarding restriction bypass.
  • Laundry Bear targets organizations in energy, law enforcement, media, NGOs, and technology.
  • The exploited flaw allows JavaScript in HTML emails to execute automatically when viewed.
  • Laundry Bear's exploit steals account data without requiring a click or visit to a phishing site.
  • International agencies from the U.S., U.K., Europe, Australia, and New Zealand issued the alert.
  • Laundry Bear's campaign targets U.S. and NATO organizations.
  • The campaign indicates espionage activities with Russian government backing.
  • The Russian group exploited the zero-day for at least five months in 2025.
  • The payload steals the last 90 days of email, the entire email directory, browser-saved passwords, and 2FA recovery codes.
  • The NSA and Proofpoint also published research on the campaign.
  • The XSS vulnerability abuses CSS @import handling to execute JavaScript.
🕒 2026-07-23 · new reporting from BleepingComputer, The Record
  • The XSS flaw has yet to receive a CVE ID.
  • The Classic UI is an Ajax-based webmail interface.
  • Zimbra 10.1.19 was released on Tuesday, July 7.
  • Zimbra Collaboration Suite (ZCS) is a communication software solution.
  • Zimbra 10.1.20 patches nine security vulnerabilities.
  • The command injection impacts the SNMP monitoring component.
  • Zimbra 10.1.20 fixes four XSS defects in the Classic Web Client.
  • Zimbra 10.1.20 resolves CVE-2026-50055, a mail forwarding restriction bypass.
  • Zimbra 10.1.20 resolves CVE-2026-10631, an access control vulnerability.
  • Zimbra 10.1.20 resolves CVE-2026-50054, an authorization issue.
  • Russian state-sponsored hacking group Laundry Bear exploits the Zimbra flaw.
  • Laundry Bear is also known as Void Blizzard.
  • Laundry Bear targets organizations in the Defense Industrial Base, government, and education.
  • The exploited flaw is CVE-2025-66376, an XSS vulnerability.
  • Laundry Bear exploited the flaw as a zero-day before November 2025.
  • CISA tagged the vulnerability as actively exploited.
  • International agencies issued an alert regarding Laundry Bear's attacks.
  • Laundry Bear previously targeted Ukrainian entities.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Russian state-sponsored hackers, identified as TA488, are actively exploiting a maximum-severity vulnerability (CVE-2026-42897) in Microsoft Exchange Server to compromise unpatched systems and steal credentials. The attacks utilize a "half-click" exploit, where merely opening an email in Outlook Web Access triggers the installation of a sophisticated new JavaScript-based implant called OWAReaper. This development indicates an advancement in the group's capabilities and poses a significant threat to organizations using vulnerable Exchange servers.

Russian threat actors, identified as Laundry Bear (TA488), are exploiting a cross-site scripting (XSS) vulnerability (CVE-2026-42897) in Microsoft Outlook Web Access (OWA) to target government entities and various sectors in the U.S. and Europe. This activity, which began in July 2026, allows the attackers to maintain access to mailboxes even after credential rotation, indicating an advancement in their exploitation techniques.

The Russian state-sponsored hacking group Laundry Bear is exploiting a zero-day cross-site scripting (XSS) vulnerability, CVE-2026-42897, in Exchange Outlook Web Access (OWA) to deploy a backdoor named OWAReaper. This vulnerability allows arbitrary JavaScript execution when users open specially crafted emails, impacting government entities and various companies in the U.S. and Europe.

The Russian state-linked hacking group Laundry Bear (TA488/Void Blizzard) exploited a vulnerability in Microsoft Outlook Web Access (OWA) using a new JavaScript implant called OWAReaper, targeting government, telecommunications, financial, hospitality, and aerospace sectors. This activity occurred shortly after their previously reported attacks on Zimbra Collaboration Suite users, indicating an improvement in the group's capabilities and a broader scope of targets.

A Russian state-supported espionage group exploited a zero-day vulnerability in Zimbra's webmail client for at least five months in 2025, stealing email and two-factor authentication codes from Western government and commercial organizations. The flaw, CVE-2025-66376, allowed attackers to execute JavaScript by simply viewing a malicious email, compromising user mailboxes.

Federal agencies from multiple Western nations have issued an alert regarding a Russian state-aligned hacking group, Laundry Bear, targeting governmental and commercial organizations through zero-click phishing emails exploiting a vulnerability in Zimbra Collaboration Suite's webmail platform. This campaign, which previously targeted Ukrainian entities, is now focusing on U.S. and NATO organizations, indicating espionage activities.

CISA has issued a warning that the Russian state-sponsored hacking group Laundry Bear (also known as Void Blizzard) is exploiting a zero-click vulnerability in Zimbra Collaboration email servers to steal account data. This exploitation, combined with phishing, affects various organizations including those in the Defense Industrial Base, government, and education, allowing attackers to exfiltrate emails and bypass MFA.

Zimbra has released updates for nine security vulnerabilities, including a critical SNMP command injection flaw and four cross-site scripting (XSS) vulnerabilities. These fixes are essential to prevent potential exploits, especially given the history of XSS vulnerabilities being targeted in similar software.

Zimbra has released patches for multiple critical vulnerabilities in its Collaboration Suite, including a command injection flaw that allows unauthenticated attackers to execute commands remotely. The update, ZCS 10.1.20, also fixes several cross-site scripting vulnerabilities and an email forwarding restriction bypass.

Zimbra has patched a critical stored cross-site scripting vulnerability in its Classic Web Client that could allow zero-click code execution via a malicious email. The flaw, which has not yet received a CVE identifier, raises significant security concerns due to potential unauthorized access to user data.

Zimbra has announced updates to fix a critical stored cross-site scripting (XSS) vulnerability in the Classic Web Client. This flaw allows specially crafted emails to execute malicious code in user sessions, risking exposure of sensitive information and account settings.

Zimbra announced a patch for a critical stored XSS vulnerability affecting its Classic Web Client. Attackers could exploit this flaw to execute malicious code via specially crafted emails, leading to potential data theft. Customers using the Classic Web Client are urged to upgrade to version 10.1.19 to secure their systems.