Vulnerabilities
Products Security index
Vulnerabilities
CVE-2026-73576
Weak JWT Signing Secret Generation Enables Token Forgery in Zimbra Collaboration
CVE-2026-73575
In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site Request Forgery (CSRF) vulnerability exists in the Exchange Web Services (EWS) endpoint of Zimbra Collaboration (ZCS) due to insufficient validation of request content types. An attacker can exploit this vulnerability by causing an authenticated user to submit a crafted request, potentially allowing unauthorized actions to be performed on behalf of the victim.
CVE-2026-73574
Local File Inclusion Allows Unauthorized Disclosure of Sensitive Files in Zimbra Classic Web Client
CVE-2026-73573
Zimbra Briefcase Path Traversal Vulnerability Allowing Sensitive File Disclosure
CVE-2026-73572
Stored XSS with Inline Attachment Preview in Zimbra Classic Web Client
