CISA Alerts on Zimbra Collaboration Suite Zero-Day XSS Flaw Exploited in Ongoing Attacks
The Cybersecurity and Infrastructure Security Agency (CISA) has identified a zero-day cross-site scripting (XSS) vulnerability within the Zimbra Collaboration Suite (ZCS), actively exploited by attackers to seize user sessions, extract data, and…
The Cybersecurity and Infrastructure Security Agency (CISA) has identified a zero-day cross-site scripting (XSS) vulnerability within the Zimbra Collaboration Suite (ZCS), actively exploited by attackers to seize user sessions, extract data, and manipulate email filters.
The identified vulnerability arises from inadequate HTML sanitization in calendar invitation files (ICS) within the Classic Web Client. Exploitation is possible through a crafted ICS entry embedding JavaScript in the event's ontoggle attribute, which executes when a user opens the corresponding email.
Product CVE ID Vulnerability Description
Zimbra Collaboration Suite (ZCS) CVE-2025-27915 Insufficient HTML sanitization in ICS files of the Classic Web Client triggers JavaScript execution via the ontoggle event, allowing arbitrary script execution in the user's session.
The identified vulnerability arises from inadequate HTML sanitization in calendar invitation files (ICS) within the Classic Web Client.
This flaw grants attackers equivalent access to users, enabling them to alter email filters, exfiltrate data, and perform unauthorized actions. CISA added this vulnerability to its Known Exploited Vulnerabilities Catalog on Mon, Oct 7, 2025, with a remediation deadline of Mon, Oct 28, 2025. ZCS administrators are urged to:
Consult vendor advisories to apply patches or workarounds promptly. Adhere to Cloud Security Technical Reference Architecture guidance under BOD 22-01 for cloud-hosted deployments. If not mitigated, consider disabling the Classic Web Client or discontinuing use of vulnerable Zimbra servers until patches are released.
CISA advises monitoring logs for suspicious email filter changes or unusual ICS attachments. Any signs of compromise should be prioritized.
This XSS flaw, with a CVSS score of 7.5, affects all supported versions of the Zimbra Collaboration Suite with the Classic Web Client. The vulnerability can be exploited via phishing campaigns or malicious calendar invites. Security teams are advised to enhance email attachment policies and scrutinize ICS files.
Conducting user awareness programs regarding unsolicited calendar invites may reduce attack success. Immediate patching and vigilant monitoring are essential to counteract this vulnerability. ZCS users should act swiftly to secure their email systems.
Based on reporting by GBHackers.
