Description
Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.
In plain language
AI Act nowCVE-2025-66376 is a Zimbra webmail bug that can let attackers run script in someone’s browser just by sending a specially crafted email; if you use Zimbra Collaboration Suite (10.x), you should treat this as an urgent risk because it has been exploited in real attacks.
CVE-2025-66376 is Classic UI stored XSS in Zimbra Collaboration Suite via malicious CSS `@import` directives injected into an HTML email message; it is triggered when a victim views the crafted email, allowing JavaScript execution in the user’s browser context without authentication or user interaction beyond viewing.
What to do now
- Check whether you run “Zimbra Collaboration Suite, Collaboration” version 10.0.x earlier than 10.0.18 or 10.1.x earlier than 10.1.13 (and whether Classic UI is in use).
- If you are on an affected version, plan an upgrade immediately to Collaboration 10.0.18 or Collaboration 10.1.13.
- If you cannot upgrade right away, follow Zimbra’s security advisory mitigation guidance at the link provided by the vendor and restrict/monitor email access as directed.
- Hunt for suspicious or unexpected emails in the timeframe of recent logins and mailbox activity, and review sign-in/session anomalies for users who viewed emails around the incident window.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:CScopeC:LConfidentialityI:LIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- Laundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42897)en-us·Help Net Security· Exploited Outlook Web Access (OWA) TA488
- Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotationen·The Hacker News· Exploited Microsoft Outlook Web Access Laundry Bear
- Srsly Risky Biz: Chipping Away at Chinese AI Risksen·Risky Business News· Research ai-ml
- Russian hackers exploit Exchange OWA zero-day for long-term mailbox accessen-us·BleepingComputer· Exploited Microsoft Exchange Outlook Web Access (OWA) Laundry Bear
- 27th July – Threat Intelligence Reporten-us·Check Point Research· Roundup
- ⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and Moreen·The Hacker News· Research ai-ml
- Week in review: ServiceNow pre-auth RCE exploited in the wild, Hugging Face breacheden-us·Help Net Security· Roundup ServiceNow AI Platform
- In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flawsen-us·SecurityWeek· PoC Dolphin X ShinyHunters
- Russian hackers exploit unpatched Zimbra servers to steal emailsen-us·Help Net Security· Exploited Zimbra Collaboration Suite Laundry Bear
- Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacksen·The Hacker News· Exploited Notepad++ UAC-0099
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2025-66376 and every CVE in our database. Create a free account — no credit card required.
Create Free Account