
A dangerous new vulnerability in Zimbra Collaboration Suite, the email and groupware platform used by thousands of businesses and universities worldwide, allows an attacker to run malicious code inside a victim’s email account simply by sending them a crafted message — no clicking on links or downloading attachments required. The vulnerability, discovered by Google’s Threat Analysis Group (GTIG), is a stored cross-site scripting flaw that injects attacker-controlled code into the Zimbra web interface. When the email is opened, the embedded script runs automatically and can access the victim’s mailbox contents, session tokens, and account settings.
Zimbra has issued a fix in version 10.1.19. Because the vulnerability requires no interaction beyond opening an email, the risk is elevated for anyone whose organization uses Zimbra and has not yet applied the patch. Google’s Threat Analysis Group typically focuses on flaws being actively used by state-sponsored hackers and commercial spyware vendors, which suggests this vulnerability may already be exploited in targeted attacks.
How to check if you’re affected
Affected versions of Zimbra Collaboration Suite include ZCS 10.0.x, 9.0.x, and 8.8.15. You can find your Zimbra version by logging into the Zimbra Admin Console (https://mail.yourorganization.com:7071/zimbraAdmin) and clicking About in the top right corner. If you see a version older than 10.1.19, your server is vulnerable. Zimbra administrators should also note that users upgrading from ZCS 10.0.x or older affected versions need to reapply the SNMP mitigation steps as described in the Zimbra release notes — the upgrade alone does not restore them automatically.
