Update Now: Critical Zimbra Classic Web Client Flaw Could Expose Mailboxes
ID: 0bf89d98-0bf2-5dc9-90c4-7e3ca25c8695
STIX ID: report--0bf89d98-0bf2-5dc9-90c4-7e3ca25c8695
Feed Name: Security Affairs
Zimbra released ZCS v10.1.19 to address a critical stored XSS in the Classic Web Client that allows specially crafted emails to run malicious code when opened, potentially exposing mailbox contents, session data and account settings; the report notes Google TAG discovered the flaw and that a related Zimbra XSS (CVE-2025-66376) has been exploited by Russia-linked APT28 in Operation GhostMail to steal credentials, 2FA codes and up to 90 days of emails, so affected organizations are urged to patch immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
