High severity7.2CISA KEVOSV Advisory· Published Jan 5, 2026· Updated Jun 17, 2026
CVE-2025-66376
CVE-2025-66376
Description
Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*Range: >=10.0.0,<10.0.18
- Range: <10.0.18, <10.1.13
Patches
Vulnerability mechanics
References
6- wiki.zimbra.com/wiki/Security_CenternvdRelease NotesVendor Advisory
- wiki.zimbra.com/wiki/Zimbra_Security_AdvisoriesnvdVendor Advisory
- wiki.zimbra.com/wiki/Zimbra_Releases/10.0.18nvdRelease Notes
- wiki.zimbra.com/wiki/Zimbra_Releases/10.1.13nvdRelease Notes
- wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_PolicynvdProduct
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
20- Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential RotationThe Hacker News · Jul 30, 2026
- Russian hackers exploit Exchange OWA zero-day for long-term mailbox accessBleepingComputer · Jul 29, 2026
- 27th July – Threat Intelligence ReportCheck Point Research · Jul 27, 2026
- ⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and MoreThe Hacker News · Jul 27, 2026
- Russian Espionage Hackers Hit Zimbra With Half-Click AttacksGovInfoSecurity · Jul 24, 2026
- In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel FlawsSecurityWeek · Jul 24, 2026
- Russian hackers exploit unpatched Zimbra servers to steal emailsHelp Net Security · Jul 24, 2026
- Russian Hackers Exploiting Zimbra Zero-Day to Steal 90 Days of EmailsCyber Security News · Jul 24, 2026
- Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 AttacksThe Hacker News · Jul 24, 2026
- Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine TargetsDark Reading · Jul 23, 2026
- Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA CodesThe Hacker News · Jul 23, 2026
- Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countriesCyberScoop · Jul 23, 2026
- International alert spotlights Russia-linked attacks on Zimbra webmailThe Record · Jul 23, 2026
- Russian hackers exploit Zimbra zero-click flaw for email theftBleepingComputer · Jul 23, 2026
- Year-long Russian attacks infect users as soon as they look at an emailThe Register Security · Jul 23, 2026
- Russian Hackers Exploit New ‘Zero-Click’ Attack Against Western OrganizationsInfosecurity Magazine · Jul 23, 2026
- Russian Global Webmail EspionageUnit 42 · Jul 23, 2026
- Zimbra urges customers to patch critical web client XSS flawBleepingComputer · Jul 10, 2026
- 23rd March – Threat Intelligence ReportCheck Point Research · Mar 23, 2026
- Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration SuiteCISA Alerts