CVE-2023-41106: Zimbra Collaboration

High severity, CVSS 7.5. EPSS: 1% chance of exploitation in the next 30 days.

An issue was discovered in Zimbra Collaboration (ZCS) before 10.0.3. An attacker can gain access to a Zimbra account. This is also fixed in 9.0.0 Patch 35 and 8.8.15 Patch 42.

Affected products

  • Zimbra Collaboration: before 8.8.15 (fixed in 8.8.15); from 10.0.0, before 10.0.3 (fixed in 10.0.3); version 8.8.15 only; version 9.0.0 only

Published 2023-12-07. Last modified 2026-06-17.