← Vulnerability feed

Vulnerability record · CVE-2025-66376 · published 5 January 2026

CVE-2025-66376: Zimbra Collaboration Classic UI stored XSS via CSS @import in email

SSynacor · Zimbra Collaboration Suite

Zimbra Collaboration Suite 10 before 10.0.18 and 10.1 before 10.1.13 allows stored cross-site scripting in the Classic UI through CSS @import directives embedded in an HTML email message. Because the payload is stored in a delivered message, it can execute in the browser of any user who views it, and the record does not state whether the flaw is limited to the Classic UI or affects other clients.

6.1 CVSS 3.1 Medium CISA KEV since 18 Mar 2026 EPSS 20% · top 2.7% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score
20%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityThe flaw is a network-reachable stored XSS with a scope change and confirmed inclusion in CISA KEV, though its CVSS base score is only 6.1 and it requires victim interaction.

What it is

Zimbra Collaboration Suite 10 before 10.0.18 and 10.1 before 10.1.13 allows stored cross-site scripting in the Classic UI through CSS @import directives embedded in an HTML email message. Because the payload is stored in a delivered message, it can execute in the browser of any user who views it, and the record does not state whether the flaw is limited to the Classic UI or affects other clients.

Impact

An attacker can run script in the context of a victim's Zimbra web session, enabling session or credential theft and actions performed as the victim. The CVSS scope change (S:C) indicates impact can extend beyond the vulnerable component.

Attack surface

Reached over the network by sending an HTML email containing a crafted CSS @import directive; no authentication is required to deliver the message, but the victim must open or view it in the Classic UI (UI:R).

Exploitation

CVE-2025-66376 was added to CISA KEV on 2026-03-18 with a remediation due date of 2026-04-01, indicating known exploitation; EPSS gives a 30-day probability of 0.19559 (97.2nd percentile). No ransomware campaign use is documented.

What to do

  • Upgrade Zimbra Collaboration to 10.0.18 or 10.1.13 (or later) per the vendor release notes.
  • If immediate patching is not possible, apply the mitigations in the vendor Security Center guidance or discontinue use of the affected Classic UI, consistent with CISA's required action.
  • Restrict or filter inbound HTML email containing CSS @import directives at the mail gateway where operationally feasible.
  • Limit use of the Classic UI in favor of a client not affected by this issue until systems are patched.
  • Track CISA KEV remediation deadlines for internet-facing Zimbra instances.

Detection

  • Search mail logs and message stores for inbound HTML messages containing CSS @import directives.
  • Monitor web proxy and Zimbra access logs for anomalous script or external resource loads originating from webmail sessions.
  • Review Zimbra webmail sessions for unexpected session activity or credential use following message viewing.
  • Audit deployed Zimbra versions against the fixed 10.0.18 and 10.1.13 releases.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-66376 to the Known Exploited Vulnerabilities catalog on 18 March 2026 as "Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 1 April 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-66376 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-45519Zimbra Collaboration postjournal service unauthenticated command executionThe postjournal service in Zimbra Collaboration Suite fails to properly neutralize input, allowing OS command injection. Because the service can be r…KEVEPSS 100%analysed9.8CVE-2022-41352Zimbra Collaboration amavis cpio path traversal arbitrary file uploadZimbra Collaboration Suite 8.8.15 and 9.0 allow an attacker to upload arbitrary files through amavis by abusing cpio archive extraction into the web-…KEVEPSS 95%analysed9.8CVE-2022-37042Zimbra Collaboration Suite mboximport auth bypass path traversal RCEZimbra Collaboration Suite 8.8.15 and 9.0 mboximport accepts a ZIP archive and extracts files without requiring an authtoken, allowing unauthenticate…KEVEPSS 92%analysed9.8CVE-2020-7796Zimbra Collaboration Suite WebEx zimlet SSRFZimbra Collaboration Suite before 8.8.15 Patch 7 is vulnerable to server-side request forgery when the WebEx zimlet is installed and its JSP is enabl…KEVEPSS 84%analysed9.8CVE-2019-9670Zimbra mailboxd Autodiscover XXE allows unauthenticated compromiseThe mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 parses XML in the Autodiscover servlet without restricting extern…KEVEPSS 100%analysed9.0CVE-2023-34192Zimbra ZCS autoSaveDraft XSS enables remote code executionZimbra Collaboration Suite 8.8.15 has a cross-site scripting flaw in the /h/autoSaveDraft function. A remote authenticated attacker can inject a craf…KEVEPSS 77%analysed8.9CVE-2026-73570Zimbra Collaboration SNMP notification OS command injectionZimbra Collaboration Suite before 10.1.20 contains an OS command injection flaw in SNMP notification processing when the optional zimbra-snmp package…KEVEPSS 12%analysed8.8CVE-2025-68645Zimbra Webmail Classic UI RestFilter local file inclusionZimbra Collaboration Suite 10.0 and 10.1 mishandle user-supplied parameters in the RestFilter servlet of the Webmail Classic UI, allowing local file …KEVEPSS 49%analysed

Source: NIST National Vulnerability Database (record CVE-2025-66376), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.