CVE-2025-66376: listed in the CISA KEV catalog CVE-2025-66376 · CVSS 7.2 HIGH · EPSS 22% · KEV 2026-03-18
Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.
Is CVE-2025-66376 exploited? Listed in the CISA KEV catalog on 2026-03-18. Federal remediation due 2026-04-01. Past that date by 136 days. EPSS puts exploitation in the next 30 days at 22%. Public exploit code: none found in monitored sources. Which products and versions are affected? No affected package list recorded here yet.
Is there a patch? No patch identifier recorded here yet.
What PlainSec published about CVE-2025-66376 Primary sources What this record does not say No affected package data. No patch identifier. KEV and EPSS are re-checked daily. Record last updated 2026-08-11.
CVE-2025-66376: listed in the CISA KEV catalog CVE-2025-66376 · CVSS 7.2 HIGH · EPSS 22% · KEV 2026-03-18
Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.
Is CVE-2025-66376 exploited? Listed in the CISA KEV catalog on 2026-03-18. Federal remediation due 2026-04-01. Past that date by 136 days. EPSS puts exploitation in the next 30 days at 22%. Public exploit code: none found in monitored sources. Which products and versions are affected? No affected package list recorded here yet.
Is there a patch? No patch identifier recorded here yet.
What PlainSec published about CVE-2025-66376 Primary sources What this record does not say No affected package data. No patch identifier. KEV and EPSS are re-checked daily. Record last updated 2026-08-11.