CISA Warns of Zimbra Collaboration Suite Vulnerability Exploited in Attacks
ID: f9411e70-f1e7-589c-893f-ff046e588d2a
STIX ID: report--f9411e70-f1e7-589c-893f-ff046e588d2a
Feed Name: cybersecurityNews.com
Threat Score
CISA has added CVE-2025-66376 — a stored XSS in the Zimbra Collaboration Suite Classic UI actively exploited via maliciously crafted emails — to its Known Exploited Vulnerabilities catalog and mandated federal agencies apply patches by April 1, 2026; Zimbra released fixes in versions 10.1.13 and 10.0.18 (also upgrading AntiSamy), and organizations still on EOL Zimbra 10.0 must migrate immediately to mitigate session theft and unauthorized access risks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
