CISA Warns of Critical Zimbra CVE-2022-27925 Exploited in Attacks
Key Takeaways A critical stored cross-site scripting (XSS) vulnerability, CVE-2025-66376, in Zimbra Collaboration Suite (ZCS) is under active exploitation. The flaw affects the Classic User Interface...
Key Takeaways
- A critical stored cross-site scripting (XSS) vulnerability, CVE-2025-66376, in Zimbra Collaboration Suite (ZCS) is under active exploitation.
- The flaw affects the Classic User Interface and can be triggered by specially crafted emails.
- Attackers can leverage this vulnerability to steal session cookies, access sensitive data, or execute arbitrary commands.
- Zimbra has released patches in versions 10.1.13 and 10.0.18 to mitigate the issue.
- CISA has issued a directive for federal agencies to apply patches by April 1, 2026, and strongly recommends all organizations adhere to this deadline.
Zimbra Collaboration Suite Flaw Actively Exploited, CISA Issues Urgent Warning
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical alert regarding a high-severity vulnerability within the Zimbra Collaboration Suite (ZCS), adding it to its Known Exploited Vulnerabilities (KEV) catalog. This security flaw, identified as CVE-2025-66376, is currently being actively exploited in real-world attacks, prompting an urgent call for all organizations utilizing Zimbra to prioritize immediate remediation efforts.
Table Of Content
The vulnerability poses a significant risk of unauthorized access and potential data compromise, making timely patching essential for maintaining system integrity and user security.
Technical Details of CVE-2025-66376
The core of the vulnerability lies in a stored cross-site scripting (XSS) issue affecting the Classic User Interface of the Zimbra Collaboration Suite. Threat actors are exploiting this weakness by embedding malicious code within specially crafted emails.
The attack mechanism leverages the abuse of Cascading Style Sheets (CSS) @import directives directly embedded within the HTML body of an email. When a recipient opens such a malicious message within the Classic UI, the embedded scripts automatically execute within the context of the user’s active session.
This unauthorized script execution circumvents standard security protocols, potentially allowing attackers to harvest session cookies, gain access to sensitive email content, or execute arbitrary commands impersonating the victim. While a direct link to ongoing ransomware campaigns has not been confirmed, the simplicity of its delivery via email makes it a highly critical threat vector.
Zimbra Releases Patches and Enhancements
Zimbra has addressed this vulnerability in its most recent patch releases, specifically versions 10.1.13 and 10.0.18. Applying these updates fully mitigates the stored XSS vulnerability. As part of a broader security overhaul, Zimbra also upgraded its AntiSamy security library to version 1.7.8 and removed outdated, potentially risky code from the platform.
Beyond critical security fixes, the 10.1.13 update introduces significant improvements to user experience and overall performance. Administrators will benefit from enhanced TLS handling, optimized memory management, and faster loading of email threads. End-users will experience a more refined Modern Web App, featuring improved drag-and-drop file management, reliable copy-paste functionality from Microsoft Office, and enhanced tag organization. Additionally, the update ensures compatibility with Outlook 2024 and maintains support for Legacy Exchange Web Services (EWS).
CISA Mandate and End-of-Life Warning
In light of the active exploitation, CISA has issued a directive mandating that all Federal Civilian Executive Branch (FCEB) agencies apply the necessary Zimbra patches by April 1, 2026. Private sector organizations are strongly advised to adhere to this same deadline. Should patching prove impossible, CISA recommends discontinuing the use of the vulnerable product immediately.
System administrators must also be aware that Zimbra version 10.0 officially reached its End of Life (EOL) on December 31, 2025. Organizations still operating on the 10.0 release cycle must plan an immediate migration to Zimbra 10.1 to maintain security compliance. Continuing to operate on an EOL platform will leave infrastructure permanently exposed to future unpatched vulnerabilities, significantly increasing risk.
What You Should Do
- Patch Immediately: Upgrade Zimbra Collaboration Suite to versions 10.1.13 or 10.0.18 without delay.
- Prioritize EOL Migration: If running Zimbra 10.0, migrate to version 10.1 immediately, as 10.0 is End of Life and no longer receives security updates.
- Consider Discontinuation: If patching or migrating is not feasible, CISA recommends discontinuing the use of vulnerable Zimbra products.
- Educate Users: Remind users about the risks of opening suspicious emails, even from seemingly trusted sources.
- Monitor Systems: Implement robust monitoring for unusual activity on Zimbra servers and connected systems.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.