logo

CISA orders feds to patch Zimbra XSS flaw exploited in attacks

ID: 9bfd1c32-9462-5c9c-96ff-3df1b0826a43

STIX ID: report--9bfd1c32-9462-5c9c-96ff-3df1b0826a43

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-03-18

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

CISA has warned of active exploitation of a high-severity stored XSS vulnerability in Zimbra Collaboration Suite (CVE-2025-66376) that can allow remote unauthenticated attackers to execute arbitrary JavaScript via malicious HTML emails; federal agencies were ordered to secure or patch affected servers by April 1. The report highlights Zimbra's history of large-scale breaches and prior abuse by state-backed actors, urging organizations to apply vendor mitigations or discontinue use if unmitigable.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.