CISA Adds Exploited Zimbra Collaboration Suite Flaw to Warning List
ID: c0d73e60-5bd8-57bd-ad92-afd1640bd10c
STIX ID: report--c0d73e60-5bd8-57bd-ad92-afd1640bd10c
Feed Name: GBHackers
Threat Score
CISA has added CVE-2025-66376 — a critical stored XSS in Zimbra Collaboration Suite Classic UI — to its Known Exploited Vulnerabilities catalog, requiring organizations to apply vendor patches by April 1, 2026; Synacor fixed the issue by upgrading the AntiSamy HTML filter to 1.7.8 and removed legacy code, and administrators are advised to update to patched versions (10.1.13 for current branch or 10.0.18 for legacy) or discontinue use if they cannot patch.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
