ICS Calendar XSS Risk: New Zimbra Zero-Day Exploit Revealed
Researchers discovered a zero-day in Zimbra webmail where malicious JavaScript injected into .ICS calendar files executes within session context — allowing attackers to steal emails, credentials, and forward mail.