Reflected Cross-Site Scripting Vulnerability in Zimbra Collaboration Suite
CVE-2026-33368

Currently unrated

Key Information:

Vendor

Zimbra

Vendor
CVE Published:
20 March 2026

What is CVE-2026-33368?

The Zimbra Collaboration Suite (ZCS) versions 10.0 and 10.1 contain a reflected XSS vulnerability in the Classic Webmail REST interface. This vulnerability arises from insufficient sanitization of user-supplied input, enabling an unauthenticated attacker to craft a malicious URL that, when accessed by a victim user, executes injected JavaScript within the context of the Zimbra webmail application. This can lead to unauthorized actions performed on behalf of the victim, posing significant security risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.