Vulnerabilities & Exploits · Web App Attack

CISA Orders Federal Patch for Zimbra XSS Flaw

The flaw affects Zimbra Classic UI and can let malicious HTML emails execute JavaScript, risking session hijack and data exposure. CISA added the bug to its exploited-vulnerabilities catalog and gave FCEB agencies two weeks under BOD 22-01 to secure affected servers.

2 sources · Mar 23

CVE-2025-66376

NVD KEV

Known exploited · CISA KEV

CVSS 7.2 HIGH: zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style… EPSS 20% (97th percentile).

CISA federal remediation date Apr 1

Timeline

Sources

Part of the PlainSec briefing for 2026-03-22

Every edition of this story: CISA Orders Federal Patch for Zimbra XSS Flaw

More from today