Vulnerabilities · 180 days ago

Russian APT Breaches Ukrainian Maritime Agency Through Zimbra Flaw

Malicious JavaScript in HTML emails executed when viewed and harvested credentials, session tokens, backup 2FA codes, browser-stored passwords, and up to 90 days of mailbox data. CISA added the flaw to its Known Exploited Vulnerabilities catalog and Zimbra released fixes in versions 10.1.13 and 10.0.18.

CVE-2025-66376

NVD KEV

Known exploited · CISA KEV

CVSS 7.2 HIGH: zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style… EPSS 20% (97th percentile).

CISA federal remediation date Apr 1

Timeline

Sources

3 sources covering this story

Entities

Part of the PlainSec briefing for 2026-03-20

Editions

Related stories