CISA Adds Exploited Zimbra Collaboration Suite Flaw to Warning List
The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability affecting the Zimbra Collaboration Suite (ZCS) to its Known Exploited Vulnerabilities (KEV) catalog.
The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability affecting the Zimbra Collaboration Suite (ZCS) to its Known Exploited Vulnerabilities (KEV) catalog.
Federal agencies and organizations using the platform must apply the necessary updates by April 1, 2026, to mitigate active exploitation risks.
Exploited Zimbra Collaboration Suite Flaw
Tracked as CVE-2025-66376, this high-severity flaw involves a stored Cross-Site Scripting (XSS) vulnerability within the Zimbra Classic UI.
The issue arises from how the software processes malicious email content, allowing attackers to use Cascading Style Sheets (CSS) @import directives embedded in HTML emails to bypass standard input filters.
If a target opens a specially crafted message, the malicious script executes within the context of their current session.
This could enable threat actors to access sensitive emails, hijack user sessions, and compromise the wider collaboration environment.
Federal agencies and organizations using the platform must apply the necessary updates by April 1, 2026, to mitigate active exploitation risks.
Synacor, the vendor behind Zimbra, has addressed this vulnerability in their latest patch releases.
The security update resolves the XSS flaw by upgrading the AntiSamy HTML filtration component to version 1.7.8 and removing the vulnerable legacy code. Administrators must update to one of the patched versions to secure their systems:
Zimbra Collaboration Suite version 10.1.13 for current branch users. Zimbra Collaboration Suite version 10.0.18 for legacy deployments.
CISA strongly advises organizations to apply these vendor mitigations immediately or discontinue using the product entirely if updates cannot be deployed.
Synacor rates the deployment risk for this patch as medium, recommending that administrators follow standard staging and testing procedures before pushing the update to production servers.
Additional Security and System Updates
Beyond patching CVE-2025-66376, the latest Zimbra updates introduce several security and usability enhancements to improve system stability and align with modern administrative needs:
Enhanced Transport Layer Security (TLS) handling according to modern RFC guidelines. Improved Amazon S3 data management and cleanup processes for mailbox migrations. New Ignite smart email search providing instant suggestions alongside LDAP-supported external email warnings. Enhanced recovery options for users to restore deleted emails, contacts, and files directly from the Trash folder. Updated Zimbra Connector for Outlook (ZCO) featuring full compatibility with Outlook 2024. Continued Exchange Web Services (EWS) compatibility for legacy Outlook clients until October 2026.
Administrators should note that Zimbra version 10.0 officially reached its End of Life (EOL) on December 31, 2025.
While version 10.0.18 provides critical security fixes for this specific CVE, organizations running the 10.0 branch must urgently plan their migration to the fully supported 10.1 series to ensure uninterrupted access to future security patches and threat mitigations.
Based on reporting by GBHackers.
