CVE-2025-66376
Known exploited · CISA KEV
CVSS 7.2 HIGH: zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style… EPSS 20% (97th percentile).
CISA federal remediation date Apr 1
Vulnerabilities & Exploits · APT / Espionage
Malicious JavaScript in HTML emails executed when viewed and harvested credentials, session tokens, backup 2FA codes, browser-stored passwords, and up to 90 days of mailbox data. CISA added the flaw to its Known Exploited Vulnerabilities catalog and Zimbra released fixes in versions 10.1.13 and 10.0.18.
3 sources · Mar 19
Known exploited · CISA KEV
CVSS 7.2 HIGH: zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style… EPSS 20% (97th percentile).
CISA federal remediation date Apr 1
SecurityWeek
Russian APT Exploits Zimbra Vulnerability Against Ukraine
Insufficient sanitization of CSS content within HTML emails leads to inline script execution when the message is opened in a browser.
originalThe Record from Recorded Future
Russian hackers exploit Zimbra flaw to breach Ukrainian maritime agency
The Russian state-backed hacker group APT28 targeted a Ukrainian government agency by exploiting a vulnerability in Zimbra webmail software.
originalBleepingComputer
Russian hackers exploit Zimbra flaw in Ukrainian govt attacks
Hackers part of APT28, a state-backed threat group linked to Russia's military intelligence service (GRU), are exploiting a Zimbra Collaboration Suite (ZCS) vulnerability in attacks targeting Ukrainian government entities.
originalPart of the PlainSec briefing for 2026-03-20
Every edition of this story: Russian APT Breaches Ukrainian Maritime Agency Through Zimbra Flaw