
The release also fixes four cross-site scripting (XSS) vulnerabilities in the Classic Web Client that could allow attackers to execute malicious scripts when users view emails in the web interface. For example, one vulnerability can be triggered through specially crafted attachment filenames and another when users render an attachment.
XSS vulnerabilities are dangerous because they execute scripts in the user’s browser in the context of the page. That gives rogue code the same privileges as the user, enabling it to perform malicious actions, exfiltrate data, or even leak session cookies.
In 2025, an XSS vulnerability in the calendar import feature of the Zimbra Classic Web Client (CVE-2025-27915) was exploited in attacks targeting Brazilian military personnel. Many other Zimbra vulnerabilities have been exploited over the years, sometimes as zero-days, especially by Russian state-sponsored APT groups, such as Fancy Bear (APT28), Cozy Bear (APT29), and Winter Vivern (TA473).
