DIRAS TAKE
Urgent: this is a pre-auth RCE requiring no login; install the 10.1.21 update promptly or block public Briefcase and OnlyOffice document editing exposure while you patch.
What is CVE-2026-93643?
An unauthenticated attacker can cause a Zimbra Collaboration Suite server to accept crafted writes that escape intended directories and lead to code execution as the zimbra user. CVE-2026-93643 targets installations where the OnlyOffice/Document Editing integration and a publicly available Briefcase document are present. A network-accessible server and access to a supported public Briefcase document are sufficient; no account or user interaction is required. The flaw impacts ZCS 10.x releases prior to 10.1.21. The weakness is classified as CWE-22 (Path Traversal).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Zimbra Zimbra Collaboration Suite (ZCS) are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 10.x | before 10.1.21 | 10.1.21 |
Is CVE-2026-93643 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-93643
- Upgrade Zimbra Collaboration Suite 10.x to 10.1.21.
- If immediate upgrade is not possible, disable or restrict OnlyOffice/Document Editing and public Briefcase document access to trusted networks.
- Monitor Zimbra server logs for anomalous file writes and for unexpected processes running as the zimbra user.
- Follow any additional mitigations published by Zimbra.
Frequently asked questions
Is CVE-2026-93643 being actively exploited?
There are no public reports of exploitation of CVE-2026-93643 as of 2026-09-29.
Which Zimbra Collaboration Suite (ZCS) versions are affected by CVE-2026-93643?
Zimbra Collaboration Suite 10.x releases before 10.1.21 are affected by CVE-2026-93643.
Is there a patch for CVE-2026-93643?
Yes, Zimbra addressed the vulnerability in version 10.1.21.
Does CVE-2026-93643 require authentication?
No; the vulnerability can be exploited without authentication when OnlyOffice/Document Editing is enabled and a supported public Briefcase document is reachable.
References
- nvd.nist.gov/vuln/detail/CVE-2026-93643
- cve.org/CVERecord?id=CVE-2026-93643
- wiki.zimbra.com/wiki/Zimbra_Security_Advisories
- All Zimbra CVEs on CVE Radar
- CVEs published in September 2026