CVE-2025-66376
Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.
Actively exploited
- In the CISA exploited-vulnerabilities catalogue since Mar 18, 2026
- US federal agencies must remediate it by Apr 1, 2026 (BOD 22-01)
- First attack observed 70 days after disclosure
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Source: CISA KEV · Aug 20, 2026 Aug 10, 2026 Aug 7, 2026 Jul 31, 2026 Jul 23, 2026 Jul 23, 2026
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:NAffected products
| Vendors | Product | Versions |
|---|---|---|
| synacor | zimbra collaboration suite | < 10.0.18 |
Related articles
MalwareThreats of the Week: AI-Powered Infostealer, Zero-Day on Industrial Switches, and Flood of CVEs in the Linux Kernel
Explore this week's top cyber threats: AI infostealer, Siemens ROX II zero-days, 432 Linux kernel CVEs, and Zimbra APT exploits.
APTUAC-0099 Leverages a Trojanized Notepad++ Plugin to Target Ukraine
UAC-0099 APT targets Ukraine via a trojanized Notepad++ plugin delivering LUNCHPOKE and BURNYBEAR payloads for espionage and cyber sabotage.
APTLaundry Bear exploits Exchange OWA zero-day: persistent and invisible espionage
Laundry Bear APT exploits an Exchange OWA zero-day (CVE-2026-42897) deploying the OWAReaper backdoor for invisible espionage and persistent mailbox access.
VulnerabilitiesZimbra Vulnerability Exploited to Enable Unauthenticated Remote Command Execution
Active exploitation of CVE-2026-73570 in Zimbra allows unauthenticated RCE. Affects versions before 10.1.20 with SNMP enabled. Upgrade to 10.1.20 or later for fix.
VulnerabilitiesZimbra CVE-2026-73570 Exploited in the Wild: Who Needs to Patch Immediately
CVE-2026-73570 in Zimbra Collaboration is actively exploited. Learn who needs to patch immediately, the vulnerability details, and security steps.
This product uses the NVD API but is not endorsed or certified by the NVD.