OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-93642

CRITICAL · CVSS 9.3 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

An unauthenticated attacker can exploit a stored cross-site scripting (XSS) vulnerability in Zimbra Modern by forging a share notification, which, when accepted by a signed-in user, allows the attacker to access the victim's mailbox data and perform actions on their behalf. This critical vulnerability poses a significant risk to organizations using Zimbra, particularly those handling sensitive information. Administrators should prioritize patching this issue to mitigate potential data breaches and unauthorized access.

CVE
CVE-2026-93642
Severity
CRITICAL
CVSS
9.3
EPSS
0.23%

Original NVD Description

An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Modern recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.