CriticalCritical vulnerability
CVE-2026-93647 (CVSS 9.3)
NVD · officialPublished Sep 25, 2026Risk 50/100
An unauthenticated calendar sender can place active markup in a COUNTER message's RFC From address. Selecting the message in Zimbra Classic triggers stored XSS, allowing the attacker to access mailbox data and act as the victim.
Technical details
CVSS
9.3
AV:NetworkAC:LowPR:NoneUI:RequiredC:HighI:HighA:None
Evidence and sources
This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source