Known Vulnerabilities for Zm-mailbox by Zimbra
Listed below are 1 of the newest known vulnerabilities associated with "Zm-mailbox" by "Zimbra".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-102372 json | GestSup versions before 3.2.62 fail to properly sanitize HTML email bodies in the IMAP LOGIN connector, allowing unauthentica... | Not Provided | 2026-09-29 | 2026-09-29 |
| CVE-2026-100718 json | Froxlor through 2.3.10 does not enforce the mail.allow_external_domains policy in the EmailSender.add API command. When an ad... | Not Provided | 2026-09-26 | 2026-09-26 |
| CVE-2026-97957 json | In the Linux kernel, the following vulnerability has been resolved: net: hinic: fix mailbox segment buffer overflow check_m... | Not Provided | 2026-09-25 | 2026-09-25 |
| CVE-2026-94132 json | Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMailing Enterprise ex... | Not Provided | 2026-09-26 | 2026-09-26 |
| CVE-2026-93647 json | An unauthenticated calendar sender can place active markup in a COUNTER message's RFC From address. Selecting the message i... | Not Provided | 2026-09-25 | 2026-09-28 |
| CVE-2026-93642 json | An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Modern recipient cl... | Not Provided | 2026-09-25 | 2026-09-25 |
| CVE-2026-93641 json | An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Classic recipient c... | Not Provided | 2026-09-25 | 2026-09-25 |
| CVE-2026-93186 json | In the Linux kernel, the following vulnerability has been resolved: cxl/mbox: Clamp mailbox output allocation to the payload... | Not Provided | 2026-09-17 | 2026-09-17 |
| CVE-2026-93096 json | In the Linux kernel, the following vulnerability has been resolved: cxl/features: Serialize multi-part Get/Set Feature trans... | Not Provided | 2026-09-17 | 2026-09-17 |
| CVE-2026-93093 json | In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Publish channel state before callbac... | Not Provided | 2026-09-17 | 2026-09-17 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Zimbra | Zm-mailbox | 8.8.9 | |||
| Application | Zimbra | Zm-mailbox | 8.8.9 | |||
| Application | Zimbra | Zm-mailbox | 8.8.9 | |||
| Application | Zimbra | Zm-mailbox | 8.8.9 | |||
| Application | Zimbra | Zm-mailbox | 8.8.9 | |||
| Application | Zimbra | Zm-mailbox | 8.8.9 | |||
| Application | Zimbra | Zm-mailbox | 8.8.9 | |||
| Application | Zimbra | Zm-mailbox | 8.8.9 | |||
| Application | Zimbra | Zm-mailbox | 8.8.9 | |||
| Application | Zimbra | Zm-mailbox | 8.8.8 | |||
| Application | Zimbra | Zm-mailbox | 8.8.8 | |||
| Application | Zimbra | Zm-mailbox | 8.8.8 | |||
| Application | Zimbra | Zm-mailbox | 8.8.8 | |||
| Application | Zimbra | Zm-mailbox | 8.8.8 | |||
| Application | Zimbra | Zm-mailbox | 8.8.8 | |||
| Application | Zimbra | Zm-mailbox | 8.8.8 | |||
| Application | Zimbra | Zm-mailbox | 8.8.8 | |||
| Application | Zimbra | Zm-mailbox | 8.8.7 | |||
| Application | Zimbra | Zm-mailbox | 8.8.6 | |||
| Application | Zimbra | Zm-mailbox | 8.8.6 |