CVE-2025-66376

9.5 CISA KEV

Synacor · Zimbra Collaboration Suite (ZCS)

A stored Cross-Site Scripting (XSS) vulnerability in the Zimbra Collaboration Suite Classic UI allows unauthenticated attackers to execute malicious scripts via crafted CSS @import directives.

Executive summary

A critical stored XSS vulnerability in Zimbra Collaboration Suite is currently being actively exploited in the wild by state-sponsored threat actors to compromise user sessions and credentials.

Vulnerability

This is a stored Cross-Site Scripting (XSS) flaw in the Classic UI caused by improper neutralization of input within CSS @import directives in HTML emails. An unauthenticated attacker can trigger this vulnerability simply by sending a malicious email that is subsequently viewed by a user, allowing for the execution of arbitrary JavaScript in the victim's browser context.

Business impact

The exploitation of this vulnerability poses a severe risk to organizational security, as it facilitates session cookie theft, credential harvesting, and the execution of unauthorized actions on behalf of legitimate users. Given the 9.5 CVSS score and its inclusion in the CISA Known Exploited Vulnerabilities catalog, this flaw represents an urgent threat to data confidentiality and integrity. Successful exploitation could lead to full account takeover, lateral movement within the network, and significant reputational damage.

Remediation

Immediate Action: Update Zimbra Collaboration Suite to version 10.0.18 or 10.1.13 immediately to apply the vendor-supplied security patches.

Proactive Monitoring: Review mail server logs for suspicious HTML email traffic containing unconventional CSS @import directives and monitor user sessions for anomalous behavior or unauthorized access attempts.

Compensating Controls: Deploy or tune Web Application Firewalls (WAF) to inspect incoming email content for malicious CSS injection patterns, though patching remains the only definitive remediation.

Exploitation status

Public Exploit Available: Yes, this vulnerability is actively exploited in the wild, and evidence of exploitation has been documented in security research regarding state-sponsored campaigns.

Analyst recommendation

The active exploitation of this vulnerability by sophisticated threat actors makes it a top-tier priority for remediation. Organizations running the affected versions of Zimbra Collaboration Suite must expedite the deployment of version 10.0.18 or 10.1.13 to prevent further compromise. Given the ease of delivery via email, failure to patch immediately leaves the organization highly susceptible to session hijacking and credential theft.

More Synacor CVEs

Sources