CVE-2025-66376
Known exploited · CISA KEV
CVSS 7.2 HIGH: zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style… EPSS 20% (97th percentile).
CISA federal remediation date Apr 1
Vulnerabilities & Exploits · Web App Attack
The flaw affects Zimbra Classic UI and can let malicious HTML emails execute JavaScript, risking session hijack and data exposure. CISA added the bug to its exploited-vulnerabilities catalog and gave FCEB agencies two weeks under BOD 22-01 to secure affected servers.
2 sources · Mar 23
Known exploited · CISA KEV
CVSS 7.2 HIGH: zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style… EPSS 20% (97th percentile).
CISA federal remediation date Apr 1
Infosecurity Magazine
CISA Orders US Government to Patch Maximum Severity Cisco Flaw
CISA added CVE-2026-20131 to its KEV catalog as it is being used in ransomware campaigns
originalBleepingComputer
CISA orders feds to patch max-severity Cisco flaw by Sunday
The Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch a maximum-severity vulnerability, CVE-2026-20131, in Cisco Secure Firewall Management Center (FMC) by Sunday, March 22.
originalBleepingComputer
CISA orders feds to patch Zimbra XSS flaw exploited in attacks
government agencies to secure their servers against an actively exploited vulnerability in the Zimbra Collaboration Suite (ZCS).
originalPart of the PlainSec briefing for 2026-03-22
Every edition of this story: CISA Orders Federal Patch for Zimbra XSS Flaw