Vulnerabilities · 176 days ago

CISA Orders Federal Patch for XSS in Zimbra Collaboration Suite

CISA directed federal agencies to patch an actively exploited stored XSS vulnerability in Zimbra Collaboration Suite (CVE-2025-66376).

CVE-2025-66376

NVD KEV

Known exploited · CISA KEV

CVSS 7.2 HIGH: zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style… EPSS 20% (97th percentile).

CISA federal remediation date Apr 1

Timeline

Sources

2 sources covering this story

Entities

Part of the PlainSec briefing for 2026-03-25

Editions

Related stories