{"id":11480,"date":"2026-03-20T10:03:36","date_gmt":"2026-03-20T10:03:36","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/03\/20\/cisa-warns-of-zimbra-collaboration-suite-vulnerability-exploited-in-attacks\/"},"modified":"2026-03-20T10:03:36","modified_gmt":"2026-03-20T10:03:36","slug":"cisa-warns-of-zimbra-collaboration-suite-vulnerability-exploited-in-attacks","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/03\/20\/cisa-warns-of-zimbra-collaboration-suite-vulnerability-exploited-in-attacks\/","title":{"rendered":"CISA Warns of Zimbra Collaboration Suite Vulnerability Exploited in Attacks"},"content":{"rendered":"<p>    CISA Warns of Zimbra Collaboration Suite Vulnerability Exploited in Attacks<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>CISA has added a high-severity vulnerability affecting the Zimbra Collaboration Suite (ZCS) to its Known Exploited Vulnerabilities (KEV) catalog.<\/p>\n<p>Tracked as CVE-2025-66376, this security flaw is currently facing active exploitation in the wild. Organizations utilizing Zimbra must urgently prioritize remediation to prevent unauthorized access and potential data compromise.<\/p>\n<p>The vulnerability is a stored cross-site scripting (XSS) issue in the Classic User Interface of the Zimbra Collaboration Suite.<\/p>\n<p>Threat actors can exploit this weakness by crafting malicious emails containing specifically formatted code. The attack relies on <a href=\"https:\/\/cybersecuritynews.com\/hackers-exploiting-css-to-evade-spam-filters\/\" target=\"_blank\" rel=\"noreferrer noopener\">abusing Cascading Style Sheets (CSS)<\/a>\u00a0@import\u00a0directives embedded directly within the HTML body of the email.<\/p>\n<p>When a target opens the malicious message in the Classic UI, the embedded scripts run automatically in the context of the user\u2019s active session.<\/p>\n<p>This execution bypasses standard security boundaries, allowing attackers to potentially <a href=\"https:\/\/cybersecuritynews.com\/hackers-hijack-mfa-enabled\/\" target=\"_blank\" rel=\"noreferrer noopener\">harvest session cookies, access sensitive email data<\/a>, or execute unauthorized commands on behalf of the victim.<\/p>\n<p>While it remains unknown whether this exploit is tied to ongoing ransomware campaigns, its ease of delivery via email makes it a critical threat.<\/p>\n<p><a href=\"https:\/\/blog.zimbra.com\/2025\/11\/patch-release-update-zimbra-10-1-13-10-0-18\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Zimbra addressed this vulnerability in recent patch releases<\/a>, specifically versions 10.1.13 and 10.0.18. Applying the patch fully mitigates the stored XSS vulnerability. As part of the security overhaul, Zimbra also upgraded the AntiSamy security library to version 1.7.8 and removed outdated, risky code from the platform.<\/p>\n<p>Beyond security fixes, the 10.1.13 update delivers substantial user experience and performance enhancements. Administrators benefit from improved TLS handling, optimized memory management, and faster loading of email threads.<\/p>\n<p>End-users gain a refined Modern Web App experience, featuring improved drag-and-drop file management, reliable copy-paste formatting from Microsoft Office, and enhanced tag organization.<\/p>\n<p>Additionally, the update ensures compatibility with Outlook 2024 and maintains support for Legacy Exchange Web Services (EWS).<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-cisa-mandate-and-eol-warning\"><strong>CISA Mandate and EOL Warning<\/strong><\/h2>\n<p>In response to the active exploitation, CISA has mandated that all Federal Civilian Executive Branch (FCEB) agencies apply the necessary Zimbra patches by April 1, 2026.<\/p>\n<p>Private organizations are strongly encouraged to follow this same deadline. If applying the patch is not possible, <a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2025-66376\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">CISA recommends discontinuing the use of the vulnerable product<\/a> immediately.<\/p>\n<p>System administrators must also note that<a href=\"https:\/\/wiki.zimbra.com\/wiki\/Zimbra_Releases\/10.1.10\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"> Zimbra version 10.0 officially reached its End of Life (EOL)<\/a> on December 31, 2025.<\/p>\n<p>Organizations still operating on the 10.0 release cycle must plan an immediate migration to Zimbra 10.1 to maintain security compliance.<\/p>\n<p>Operating on an EOL platform will leave infrastructure permanently exposed to future unpatched vulnerabilities.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/zimbra-vulnerability-exploited-attacks\/\">CISA Warns of Zimbra Collaboration Suite Vulnerability Exploited in Attacks<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/zimbra-vulnerability-exploited-attacks\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>CISA Warns of Zimbra Collaboration Suite Vulnerability Exploited in Attacks CISA has added a high-severity vulnerability affecting the Zimbra Collaboration Suite (ZCS) to its Known Exploited Vulnerabilities (KEV) catalog. Tracked as CVE-2025-66376, this security flaw is currently facing active exploitation in the wild. Organizations utilizing Zimbra must urgently prioritize remediation to prevent unauthorized access and [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,2169,648],"tags":[130],"class_list":["post-11480","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-exploit","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11480"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=11480"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11480\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=11480"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=11480"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=11480"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}