CVE-2026-93647
EUVD-2026-8710225.09.2026, 14:17
An unauthenticated calendar sender can place active markup in a COUNTER message's RFC From address. Selecting the message in Zimbra Classic triggers stored XSS, allowing the attacker to access mailbox data and act as the victim.
Awaiting analysis
This vulnerability is currently awaiting analysis.