CISA orders feds to patch Zimbra XSS flaw exploited in attacks
ID: 9bfd1c32-9462-5c9c-96ff-3df1b0826a43
STIX ID: report--9bfd1c32-9462-5c9c-96ff-3df1b0826a43
Feed Name: Bleeping Computer
CISA has warned of active exploitation of a high-severity stored XSS vulnerability in Zimbra Collaboration Suite (CVE-2025-66376) that can allow remote unauthenticated attackers to execute arbitrary JavaScript via malicious HTML emails; federal agencies were ordered to secure or patch affected servers by April 1. The report highlights Zimbra's history of large-scale breaches and prior abuse by state-backed actors, urging organizations to apply vendor mitigations or discontinue use if unmitigable.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
