Sale of a 1-Day Exploit for Outlook Web App and Zimbra

Dark Web2026-08-25, 11:55
For informational purposes only.
Vulnerability type: XSS Affected products: Outlook Web App / Microsoft Exchange Server 2016, 2019, and Subscription Edition; Zimbra
The seller claims to be offering a 1-day exploit for Outlook Web App (Outlook on the web). According to the seller, the vulnerability affects Microsoft Exchange Server 2016, 2019, and Subscription Edition and supports multiple XSS exploitation scenarios. The seller also claims that, in the case of Outlook/Exchange, the exploit chain can ultimately be used to create a new administrative account in Active Directory.
For Zimbra, XSS exploitation is also claimed, but without the ability to create an administrative account.
Outlook Web App (Outlook on the web) is the browser-based interface for Microsoft Exchange Server, allowing users to access corporate email, calendars, and contacts.
Zimbra is an enterprise email and collaboration platform that can be deployed on-premises, in a private cloud, or through a hosting provider.
Microsoft Exchange remains one of the most widely used enterprise email platforms. According to 6sense, its dataset tracks approximately 19,300 organizations using Microsoft Exchange Server.
Zimbra also has a substantial global footprint. According to Zimbra, more than 200 million mailboxes have been deployed worldwide, with the platform used by over 6,000 organizations across 127 countries.
Vendors
Microsoft
Zimbra
Products
Microsoft Exchange Server 2016
Microsoft Exchange Server 2019
Microsoft Exchange Server Subscription Edition
Outlook Web App
Zimbra