CVE-2025-66376
Sfruttamento noto · CISA KEV
CVSS 7.2 HIGH: zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style… EPSS 20% (97º percentile).
Data di correzione federale CISA 1 apr
Vulnerabilità · 194 giorni fa
JavaScript nascosto nell'HTML delle email veniva eseguito all'apertura e ha permesso il furto di credenziali, token di sessione, codici 2FA di backup, password salvate e fino a 90 giorni di posta. CISA ha aggiunto la vulnerabilità al catalogo KEV e Zimbra ha rilasciato patch nelle versioni 10.1.13 e 10.0.18.
Sfruttamento noto · CISA KEV
CVSS 7.2 HIGH: zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style… EPSS 20% (97º percentile).
Data di correzione federale CISA 1 apr
3 fonti che coprono questa storia
Russian APT Exploits Zimbra Vulnerability Against Ukraine
Insufficient sanitization of CSS content within HTML emails leads to inline script execution when the message is opened in a browser.
The Record from Recorded Future
Russian hackers exploit Zimbra flaw to breach Ukrainian maritime agency
The Russian state-backed hacker group APT28 targeted a Ukrainian government agency by exploiting a vulnerability in Zimbra webmail software.
Russian hackers exploit Zimbra flaw in Ukrainian govt attacks
Hackers part of APT28, a state-backed threat group linked to Russia's military intelligence service (GRU), are exploiting a Zimbra Collaboration Suite (ZCS) vulnerability in attacks targeting Ukrainian government entities.
Part of the PlainSec briefing for 2026-03-20