logo

CISA Warns of Zimbra Collaboration Suite Vulnerability Exploited in Attacks

ID: f9411e70-f1e7-589c-893f-ff046e588d2a

STIX ID: report--f9411e70-f1e7-589c-893f-ff046e588d2a

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-03-19

Date Updated: 2026-04-21

Author: Abinaya

...
...

CISA has added CVE-2025-66376 — a stored XSS in the Zimbra Collaboration Suite Classic UI actively exploited via maliciously crafted emails — to its Known Exploited Vulnerabilities catalog and mandated federal agencies apply patches by April 1, 2026; Zimbra released fixes in versions 10.1.13 and 10.0.18 (also upgrading AntiSamy), and organizations still on EOL Zimbra 10.0 must migrate immediately to mitigate session theft and unauthorized access risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.