CISA orders feds to patch Zimbra XSS flaw exploited in attacks
U.S. government organizations are required by CISA to protect their servers from a Zimbra Collaboration Suite (ZCS) vulnerability that is being actively exploited.
Hundreds of millions of people worldwide, including thousands of organizations and hundreds of government bodies, use the widely used email and collaboration software suite Zimbra.
This high-severity security vulnerability, known as CVE-2025-66376 and fixed in early November, is caused by a stored cross-site scripting (XSS) vulnerability in the Classic UI that remote unauthenticated attackers might exploit by leveraging Cascading Style Sheets (CSS) @import directives in email HTML.
The impact of a successful CVE-2025-66376 attack can probably be exploited to execute arbitrary JavaScript via malicious HTML-based emails,...










