OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-93647

CRITICAL · CVSS 9.3 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

An unauthenticated calendar sender can exploit a vulnerability in Zimbra Classic by injecting active markup into a COUNTER message's RFC From address, leading to stored cross-site scripting (XSS). This allows attackers to access mailbox data and perform actions on behalf of the victim. Organizations using Zimbra Classic should prioritize patching this critical vulnerability to protect against potential data breaches and unauthorized access.

CVE
CVE-2026-93647
Severity
CRITICAL
CVSS
9.3
EPSS
0.23%

Original NVD Description

An unauthenticated calendar sender can place active markup in a COUNTER message's RFC From address. Selecting the message in Zimbra Classic triggers stored XSS, allowing the attacker to access mailbox data and act as the victim.