CVE-2025-66376 is a stored Cross-Site Scripting (XSS) vulnerability impacting Zimbra Collaboration (ZCS) versions 10 before 10.0.18 and 10.1 before 10.1.13, enabling attackers to inject malicious code through CSS @import directives within HTML email messages. Rated Medium with a CVSS score of 6.1, this flaw has a network attack vector and low complexity, requiring user interaction to achieve low impacts on confidentiality and integrity. The vulnerability is actively exploited in the wild, listed in CISA's KEV catalog, with reports indicating Russian APT groups are leveraging it against Ukrainian government entities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.0, < 10.0.18CPE match | cpe:2.3:a:zimbra:collaboration:*:*:*:*:*:*:*:* | ||
>= 10.1, < 10.1.13CPE match | cpe:2.3:a:zimbra:collaboration:*:*:*:*:*:*:*:* | ||
>= 10.0.0, < 10.0.18CPE matchmatch criteria | cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:* | ||
>= 10.1.0, < 10.1.13CPE matchmatch criteria | cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.