OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-93641

CRITICAL · CVSS 9.3 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

An unauthenticated attacker can exploit a stored cross-site scripting (XSS) vulnerability in Zimbra Classic by forging a share notification, which, when accepted by a signed-in user, allows the attacker to execute malicious scripts in the context of the victim's session. This could lead to unauthorized access to sensitive mailbox data and potentially enable the attacker to impersonate the victim. Organizations using Zimbra Classic should prioritize patching this vulnerability to safeguard user data and prevent account compromise.

CVE
CVE-2026-93641
Severity
CRITICAL
CVSS
9.3
EPSS
0.27%

Original NVD Description

An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Classic recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.