CVE-2025-66376
Sfruttamento noto · CISA KEV
CVSS 7.2 HIGH: zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style… EPSS 20% (97º percentile).
Data di correzione federale CISA 1 apr
Vulnerabilità ed exploit · Attacco ad app web
CISA ha ordinato alle agenzie federali di mettere in sicurezza i server Zimbra entro il 1 aprile ai sensi di BOD 22-01. La vulnerabilità è una stored XSS nel Classic UI (CVE-2025-66376) sfruttata in attacchi che può eseguire JavaScript via email HTML, con rischio di session hijack e esposizione di dati.
2 fonti · 23 mar
Sfruttamento noto · CISA KEV
CVSS 7.2 HIGH: zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style… EPSS 20% (97º percentile).
Data di correzione federale CISA 1 apr
Infosecurity Magazine
CISA Orders US Government to Patch Maximum Severity Cisco Flaw
CISA added CVE-2026-20131 to its KEV catalog as it is being used in ransomware campaigns
originaleBleepingComputer
CISA orders feds to patch max-severity Cisco flaw by Sunday
The Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch a maximum-severity vulnerability, CVE-2026-20131, in Cisco Secure Firewall Management Center (FMC) by Sunday, March 22.
originaleBleepingComputer
CISA orders feds to patch Zimbra XSS flaw exploited in attacks
government agencies to secure their servers against an actively exploited vulnerability in the Zimbra Collaboration Suite (ZCS).
originalePart of the PlainSec briefing for 2026-03-22
Every edition of this story: CISA ordina patch immediata per XSS in Zimbra