Earlier this year, cyberattacks against the Brazilian military used a zero-day exploit of a now-patched security flaw in Zimbra Collaboration.
A stored cross-site scripting (XSS) vulnerability in the Classic Web Client, identified as CVE-2025-27915 (CVSS score: 5.4), occurs when HTML content in ICS calendar files is not sufficiently sanitized, leading to arbitrary code execution.
A description of the vulnerability in the NIST National Vulnerability Database (NVD) states that when a user opens an email message with a malicious ICS entry, the embedded JavaScript runs via an ontoggle event inside a element.
This gives the attacker the ability to execute any JavaScript code inside the victim’s session, which could result in illegal activities like using email filters to reroute communications to an address under the attacker’s control read more about Zimbra Zero-Day Exploited to Target Brazilian Military via Malicious ICS Files.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
