CVE-2025-27915
9.5 CISA KEVSynacor · Zimbra Collaboration Suite (ZCS)
A stored cross-site scripting (XSS) vulnerability in the Zimbra Classic Web Client allows attackers to execute arbitrary JavaScript by sending malicious ICS files to victims.
Executive summary
A critical stored cross-site scripting vulnerability in Zimbra Collaboration Suite is currently being exploited in the wild, posing a significant risk of account compromise and data exfiltration.
Vulnerability
This is a stored cross-site scripting (XSS) flaw in the Classic Web Client that occurs due to improper sanitization of HTML content within ICS files. An attacker can trigger the execution of arbitrary JavaScript within a victim's session when they view a specially crafted email, requiring authenticated user interaction to successfully execute the payload.
Business impact
The vulnerability carries a CVSS score of 9.5, reflecting its potential for severe impact on organizational security. A successful exploit allows an attacker to hijack user sessions, which can lead to unauthorized actions such as modifying email filters to redirect communications or exfiltrating sensitive corporate data. Given the active exploitation status, this flaw represents an immediate threat to the confidentiality and integrity of email environments.
Remediation
Immediate Action: Administrators must immediately upgrade to the patched versions: ZCS 9.0.0/P44, ZCS 10.0.13, or ZCS 10.1.5.
Proactive Monitoring: Security teams should monitor mail logs for suspicious filtering activity or unexpected redirection rules created by users.
Compensating Controls: Deploy Web Application Firewall (WAF) rules designed to identify and block malicious ICS attachments or suspicious
Exploitation status
Public Exploit Available: Yes, a detection template exists via Nuclei.
Analyst recommendation
Due to the confirmed active exploitation and the high severity of this vulnerability, immediate remediation is required. Organizations should prioritize patching their ZCS instances to the versions specified above to prevent attackers from gaining unauthorized access to user accounts and sensitive communications.