CVE-2025-66376
published 2026-01-05CVE-2025-66376: Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an…
PriorityP180medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-04-01
Exploited in the wild
EPSS
21.97%
97.5th percentile
Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| synacor | zimbra_collaboration_suite | >= 10.0.0 < 10.0.18 | 10.0.18 |
| synacor | zimbra_collaboration_suite | >= 10.1.0 < 10.1.13 | 10.1.13 |
| zimbra | collaboration | >= 10.0 < 10.0.18 | 10.0.18 |
| zimbra | collaboration | >= 10.1 < 10.1.13 | 10.1.13 |
Detection & IOCsextracted from sources · hover to see the quote
- →The exploit is delivered entirely within the HTML body of a single email — no attachments, no links, no macros. Detect malicious HTML emails containing CSS @import directives targeting Zimbra Classic UI users. ↗
- →The payload is an obfuscated JavaScript delivered via CSS @import directives in HTML email, executing silently in the browser when the email is opened in a vulnerable Zimbra Classic UI webmail session. ↗
- →Post-exploitation activity includes credential harvesting, session token theft, backup 2FA code exfiltration, browser-saved password theft, and mailbox content exfiltration going back 90 days. Monitor for anomalous DNS and HTTPS exfiltration from Zimbra servers. ↗
- →The attack vector is a stored XSS via CSS @import directives in HTML email rendered by the Zimbra Classic UI. Inspect inbound emails for CSS @import usage in HTML bodies as a detection signal. ↗
- →Campaign is tracked as 'Operation GhostMail' by Seqrite Labs; use this name to pivot on threat intelligence and correlate related APT28 activity targeting Ukrainian government entities. ↗
- ·Vulnerability affects Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 only. Versions 10.0.18+ and 10.1.13+ are patched. ↗
- ·The XSS is specific to the Classic UI of Zimbra webmail; users or deployments not using the Classic UI may not be directly exploitable via this vector. ↗
- ·Exploitation requires the victim to open the malicious email in a vulnerable Zimbra webmail session; the attack is triggered client-side in the browser. ↗
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
vulncheck7.2HIGH
cisa6.1MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability
cisa·2026-03-18·CVSS 6.1
CVE-2025-66376 [MEDIUM] CWE-79 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability
Vulnerability: Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability
Affected: Synacor Zimbra Collaboration Suite (ZCS)
Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability in the Classic UI where attackers could abuse Cascading Style Sheets (CSS) @import directives in email HTML.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories ; https://nvd.nist.gov/vuln/detail/CVE-2025-66376
Remediation Due Date: 2026-04-01
GHSA
GHSA-h7wg-85fj-3c6g: Zimbra Collaboration (ZCS) 10 before 10
ghsa_unreviewed·2026-01-05
CVE-2025-66376 [HIGH] CWE-79 GHSA-h7wg-85fj-3c6g: Zimbra Collaboration (ZCS) 10 before 10
Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.
VulnCheck
Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability
vulncheck·2025·CVSS 7.2
CVE-2025-66376 [HIGH] CWE-79 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability
Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability
Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability in the Classic UI where attackers could abuse Cascading Style Sheets (CSS) @import directives in email HTML.
Affected: Synacor Zimbra Collaboration Suite (ZCS)
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://www.seqrite.com/blog/operation-ghostmail-zimbra-xss-russian-apt-ukraine/; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Remediation Due: 2026-04-01
No detection rules found.
No public exploits indexed.
Recorded Future
July 2026 CVE Landscape
blogs_recorded_future·2026-08-07·CVSS 9.8
CVE-2025-3248 [CRITICAL] July 2026 CVE Landscape
## July 2026 CVE Landscape
In July 2026, Insikt Group® identified 85 high-impact vulnerabilities that should be prioritized for remediation , 36 of which had a Very Critical Recorded Future Risk Score. This represents a 44% increase from last month. 26 of these vulnerabilities were surfaced through the US Cybersecurity and Infrastructure Security Agency (CISA)’s Known Exploited Vulnerabilities (KEV) catalog, 55 were reported by vendors, and four were primarily surfaced through honeypot data.
The 85 vulnerabilities in this report affected products from 61 vendors, with Microsoft accounting for approximately 12% of the vulnerabilities. The remaining exposure was concentrated across a range of enterprise software, security products, network infrastructure, developer tooling, and cloud platf
Hackernews
Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
blogs_hackernews·2026-07-30·CVSS 6.1
CVE-2026-42897 [MEDIUM] Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another vulnerability, this time in Microsoft Outlook Web Access (OWA), to target U.S. and European government entities, as well as the telecommunications, financial, hospitality, and aerospace sectors.
The activity, which began on July 22, 2026, involves the weaponization of CVE-2026-42897 (CVSS score: 8.1), a cross-site scripting (XSS) vulnerability in OWA. It was flagged by Microsoft as having been ex
Checkpoint
27th July – Threat Intelligence Report
blogs_checkpoint·2026-07-27
CVE-2026-16232 27th July – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 27th July – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 27th July, please download our Threat Intelligence Bulletin.
TOP ATTACKS AND BREACHES
Nichirei, a Japan-based frozen-food supplier and logistics company, has experienced a ransomware attack that disrupted shipping operations and affected approximately 5,000 customers. KFC Japan warned of possible shortages. Nichirei confirmed personal data theft, while the RansomHouse group claimed responsibility and published a subset of the stol
Hackernews
⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More
blogs_hackernews·2026-07-27
CVE-2026-16232 ⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More
Monday starts with the usual promise that everything is under control. Then the logs wake up.
This week, trusted tools crossed lines, old flaws found new work, exposed systems stayed exposed, and attackers kept hiding inside normal-looking services. Nothing looked strange at first. That helped.
That is the mood. Here is the full recap.
## ⚡ Threat of the Week
OpenAI Says Its AI Agent Went Rogue and Targeted Hugging Face - OpenAI disclosed that it lost control of two AI models during a security evaluation that ended in a breach o
Hackernews
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
blogs_hackernews·2026-07-24·CVSS 6.1
CVE-2025-66376 [MEDIUM] Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra's webmail client.
The payload goes after the last 90 days of email, the organization's entire email directory, the password saved in the browser and the codes kept for two-factor recovery. Opening the message was enough to start it.
The NSA , CISA and partner agencies published a joint advisory on the campaign Thursday, alongside research from Palo Alto Networks' Unit 42 and Proofpoint.
The advisory calls the technique "a view-ba
Hackernews
Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
blogs_hackernews·2026-07-24
CVE-2025-66376 Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a malicious program that's dressed up as a Notepad++ plugin to compromise Windows systems.
The activity has been attributed by the agency to a threat cluster it tracks as UAC-0099 , a Russia-aligned group that has previously observed weaponizing security flaws in WinRAR software to deliver a malware strain called LONEPAGE. Other cyber attacks mounted by the adversary have employed phishing emails as an initial access method to deploy MATCHBOIL, MATCHWO
Unit42
Russian Global Webmail Espionage
blogs_unit42·2026-07-23·CVSS 6.1
CVE-2025-66376 [MEDIUM] Russian Global Webmail Espionage
## Russian Global Webmail Espionage
Unit 42
Published: July 23, 2026
Cybercrime
Threat Research
CL-STA-1114
JavaScript
Javascript injection
Nation-state
Obfuscation
Phishing
Zimbra webmail
## Executive Summary
Unit 42 has observed a persistent cyberespionage campaign we track as CL-STA-1114. This activity cluster overlaps with activity from a Russian threat actor tracked by other vendors as Void Blizzard and LAUNDRY BEAR.
The attackers behind this campaign targeted Zimbra webmail in organizations in the following sectors:
Governments
Defense
Transportation
NATO member states
Ukraine
Commonwealth of Independent States (CIS) countries
Africa
Unique to this campaign, the group leveraged zero-click phishing emails that exploit a vulnerability in the Zimbra Collaboratio
Bleepingcomputer
Over 10,000 Zimbra servers vulnerable to ongoing XSS attacks
blogs_bleepingcomputer·2026-04-24·CVSS 6.1
CVE-2025-48700 [MEDIUM] Over 10,000 Zimbra servers vulnerable to ongoing XSS attacks
## Over 10,000 Zimbra servers vulnerable to ongoing XSS attacks
## Sergiu Gatlan
Over 10,000 Zimbra Collaboration Suite (ZCS) instances exposed online are vulnerable to ongoing attacks exploiting a cross-site scripting (XSS) security flaw, according to nonprofit security organization Shadowserver.
Zimbra is a popular email and collaboration software suite used by hundreds of millions of people worldwide, including hundreds of government agencies and thousands of businesses.
The vulnerability (tracked as CVE-2025-48700 ) affects ZCS 8.8.15, 9.0, 10.0, and 10.1 and can allow unauthenticated attackers to access sensitive information after executing arbitrary JavaScript within the user's session.
Synacor released security patches to address the flaw in June 2025, when it warned that CVE
Hackernews
CISA Adds 8 Exploited Flaws to KEV, Sets April-May 2026 Federal Deadlines
blogs_hackernews·2026-04-21·CVSS 7.5
CVE-2023-27351 [HIGH] CISA Adds 8 Exploited Flaws to KEV, Sets April-May 2026 Federal Deadlines
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## CISA Adds 8 Exploited Flaws to KEV, Sets April-May 2026 Federal Deadlines
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added eight new vulnerabilities to its Known Exploited Vulnerabilities ( KEV ) catalog, including three flaws impacting Cisco Catalyst SD-WAN Manager, citing evidence of active exploitation.
The list of vulnerabilities is as follows -
CVE-2023-27351 (CVSS score: 8.2) - An improper authentication vulnerability in PaperCut NG/MF that could allow an attacker to bypass authentication on affected installations via the SecurityRequestFilter class.
CVE-2024-27199 (CVSS score: 7.3) -
Checkpoint
23rd March – Threat Intelligence Report
blogs_checkpoint·2026-03-23
CVE-2026-33017 23rd March – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 23rd March – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 23rd March, please download our Threat Intelligence Bulletin.
TOP ATTACKS AND BREACHES
Navia Benefit Solutions, a United States-based employee benefits administrator, has disclosed a breach affecting more than 2.6 million individuals after unauthorized access and potential data exfiltration occurred between December 22, 2025 and January 15, 2026. Exposed information may include personal, health, and benefits dat
Bleepingcomputer
Russian hackers exploit Zimbra flaw in Ukrainian govt attacks
blogs_bleepingcomputer·2026-03-19·CVSS 7.2
CVE-2025-66376 [HIGH] Russian hackers exploit Zimbra flaw in Ukrainian govt attacks
## Russian hackers exploit Zimbra flaw in Ukrainian govt attacks
## Sergiu Gatlan
Hackers part of APT28, a state-backed threat group linked to Russia's military intelligence service (GRU), are exploiting a Zimbra Collaboration Suite (ZCS) vulnerability in attacks targeting Ukrainian government entities.
This high-severity security flaw (tracked as CVE-2025-66376 and patched in early November) stems from a stored cross-site scripting (XSS) that unauthenticated attackers can exploit to gain remote code execution (RCE) and compromise the Zimbra server and the target's email account.
On Wednesday, the Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its catalog of vulnerabilities exploited in the wild . CISA also ordered Federal Civilian Executive Branch (
Bleepingcomputer
CISA orders feds to patch Zimbra XSS flaw exploited in attacks
blogs_bleepingcomputer·2026-03-18·CVSS 7.2
CVE-2025-66376 [HIGH] CISA orders feds to patch Zimbra XSS flaw exploited in attacks
## CISA orders feds to patch Zimbra XSS flaw exploited in attacks
## Sergiu Gatlan
CISA has ordered U.S. government agencies to secure their servers against an actively exploited vulnerability in the Zimbra Collaboration Suite (ZCS).
Zimbra is a very popular email and collaboration software suite used by hundreds of millions of people worldwide, including thousands of businesses and hundreds of government agencies.
Tracked as CVE-2025-66376 and patched in early November, this high-severity security flaw stems from a stored cross-site scripting (XSS) weakness in the Classic UI that remote unauthenticated attackers could exploit by abusing Cascading Style Sheets (CSS) @import directives in email HTML.
While Synacor (the company behind Zimbra) didn't share any details on the impact of a
Wiz
CVE-2025-67809 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.1
CVE-2025-67809 [MEDIUM] CVE-2025-67809 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-67809 :
Zimbra Collaboration Server vulnerability analysis and mitigation
An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A hardcoded Flickr API key and secret are present in the publicly accessible Flickr Zimlet used by Zimbra Collaboration. Because these credentials are embedded directly in the Zimlet, any unauthorized party could retrieve them and misuse the Flickr integration. An attacker with access to the exposed credentials could impersonate the legitimate application and initiate valid Flickr OAuth flows. If a user is tricked into approving such a request, the attacker could gain access to the user s Flickr data. The hardcoded credentials have since been removed from the Zimlet code, and the associated key has been revoked.
Source : NVD
## 4.7
Wiz
CVE-2025-68645 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.1
CVE-2025-68645 [MEDIUM] CVE-2025-68645 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-68645 :
Zimbra Collaboration Server vulnerability analysis and mitigation
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper handling of user-supplied request parameters in the RestFilter servlet. An unauthenticated remote attacker can craft requests to the /h/rest endpoint to influence internal request dispatching, allowing inclusion of arbitrary files from the WebRoot directory.
Source : NVD
## 8.8
Score
Published December 22, 2025
Severity HIGH
CNA Score 8.8
Affected Technologies
Zimbra Collaboration Server
Has Public Exploit Yes
Has CISA KEV Exploit Yes
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 97.7
Exploitation Probabil
Wiz
CVE-2025-66376 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.1
CVE-2025-66376 [MEDIUM] CVE-2025-66376 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-66376 :
Zimbra Collaboration Server vulnerability analysis and mitigation
Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.
Source : NVD
## 6.1
Score
Published January 5, 2026
Severity MEDIUM
CNA Score 7.2
Affected Technologies
Zimbra Collaboration Server
Has Public Exploit Yes
Has CISA KEV Exploit Yes
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 93
Exploitation Probability (EPSS) 10
Affected packages and libraries
cpe:2.3:a:zimbra:collaboration
Sources
NVD
Linux Severity MEDIUM Has Fix Added at: Jan 06, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud
https://wiki.zimbra.com/wiki/Security_Centerhttps://wiki.zimbra.com/wiki/Zimbra_Releases/10.0.18#Security_Fixeshttps://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.13#Security_Fixeshttps://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policyhttps://wiki.zimbra.com/wiki/Zimbra_Security_Advisorieshttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-66376
2026-01-05
Published
2026-03-18
Added to CISA KEV
Exploited in the wild