CVE detail
CVE-2025-66376
Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 13
- within the 30d window
- Peak daily
- 5
- highest bucket
Evidence
Source links by recency
20 source links · newest first
- Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential RotationThe Hacker News
inancial, hospitality, and aerospace sectors. The activity, which began on July 22, 2026, involves the weaponization of CVE-2026-42897 (CVSS score: 8.1), a cross-site scripting (XSS) vulnerability in OWA. It was flagged by Microsoft as having been exploited in attacks as far back as May 2026. Enterprise security company Proofpoint has attributed the ac
newsthehackernews.comJul 30, 2026, 7:40 AM - 27th July – Threat Intelligence ReportCheck Point Research
,000 artifacts and a campaign that recorded over 77,000 requests. VULNERABILITIES AND PATCHES Check Point has addressed CVE-2026-16232, an authentication bypass vulnerability in SmartConsole that is under active exploitation, affecting a handful of customers. The flaw allows remote attackers to bypass authentication and gain administrative access to Ch
vendorresearch.checkpoint.comJul 27, 2026, 4:00 PM - ⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and MoreThe Hacker News
products, including a critical flaw that has come under active exploitation in the wild. The security flaw, tracked as CVE-2026-16232 (CVSS score: 9.3), is an authentication bypass affecting the Check Point SmartConsole login process that allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with ful
newsthehackernews.comJul 27, 2026, 2:10 PM - In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel FlawsSecurityWeek
that can be chained together to achieve persistent root-level access. By exploiting an arbitrary file disclosure flaw (CVE-2025-40948), an attacker can gather sensitive system intelligence to facilitate a subsequent privilege escalation via command injection (CVE-2025-40947). The compromise is then cemented using a third vulnerability (CVE-2025-40949)
newswww.securityweek.comJul 24, 2026, 2:20 PM - Russian hackers exploit unpatched Zimbra servers to steal emailsHelp Net Security
get into police employee accounts. Attackers weaponize Zimbra XSS vulnerability The attackers’ latest campaign targets CVE-2025-66376, a cross-site scripting (XSS) vulnerability in the Zimbra web-based email and collaboration suite that was patched in November 2025. The advisory notes the group kept using the exploit even after the fix came out, meani
newswww.helpnetsecurity.comJul 24, 2026, 12:09 PM - UAC-0099 Is Now Hiding Malware Inside a Fake Notepad++ Plugin to Target Ukrainian OrganizationsSecurity Affairs
ern government and commercial organizations since at least July 2025. That campaign uses a “half-click” exploit abusing CVE-2025-66376 to deliver malicious JavaScript called ZimReaper, which can harvest email communications without requiring the victim to click anything beyond opening a malicious email in a vulnerable webmail client. The U.S. governmen
newssecurityaffairs.comJul 24, 2026, 9:54 AM Bear (aka Void Blizzard) is targeting organizations using unpatched Zimbra Collaboration servers. The attackers exploit CVE-2025-66376 , an XSS flaw that allows malicious JavaScript embedded in HTML emails to run automatically when viewed, enabling account theft without user interaction. The vulnerability was exploited as a zero-day before being patche
newssecurityaffairs.comJul 24, 2026, 8:31 AMhas been targeting ZCS customers since July 2025. Laundry Bear actors used a zero-day vulnerability in ZCS , tracked as CVE-2025-66376, in a phishing campaign that featured what experts describe as a "half-click exploit" to breach Zimbra webmail servers. "Unlike traditional phishing campaigns that persuade a user into taking an action, such as clicking
newswww.darkreading.comJul 23, 2026, 9:23 PM- Russian hackers exploit Zimbra zero-click flaw for email theftBleepingComputer
ation, energy, law enforcement, media, non-governmental organizations, and technology. The attackers exploit the Zimbra CVE-2025-66376 flaw, a cross-site scripting (XSS) vulnerability affecting Zimbra Collaboration Suite's Classic UI. The flaw allows JavaScript embedded in specially crafted HTML emails to execute automatically when a victim views the m
newswww.bleepingcomputer.comJul 23, 2026, 4:49 PM - Year-long Russian attacks infect users as soon as they look at an emailThe Register Security
on the covert acquisition of email data,” according to the joint security alert. The Russians’ latest campaign targets CVE-2025-66376, a cross-site scripting (XSS) vulnerability in the Zimbra web-based email and collaboration suite that was patched in November 2025 – but Moscow's attackers began exploiting it long before then. This type of vulnerabili
newswww.theregister.comJul 23, 2026, 4:47 PM - Russian Hackers Exploit New ‘Zero-Click’ Attack Against Western OrganizationsInfosecurity Magazine
ry Bear, also known as Void Blizzard and UAC-0190 . The Laundry Bear campaign exploits a zero-day vulnerability in ZCS (CVE-2025-66376) which was publicly disclosed in November 2025 and uses a zero-click exploit coined “beehive” to steal emails and other sensitive data. Unlike traditional phishing campaigns which require a user to be socially engineere
newswww.infosecurity-magazine.comJul 23, 2026, 3:50 PM rst exploited and continues to be successfully exploited. The vulnerability, Common Vulnerabilities and Exposures (CVE) CVE-2025-66376 , was patched in November 2025. This demonstrates LAUNDRY BEAR’s intent and ability to deploy increasingly sophisticated technical capabilities. Unlike traditional phishing campaigns that persuade a user into taking an
governmentwww.cisa.govJul 23, 2026, 12:00 PMen leak session cookies. In 2025, an XSS vulnerability in the calendar import feature of the Zimbra Classic Web Client (CVE-2025-27915) was exploited in attacks targeting Brazilian military personnel . Many other Zimbra vulnerabilities have been exploited over the years, sometimes as zero-days, especially by Russian state-sponsored APT groups, such as
newswww.csoonline.comJul 22, 2026, 8:26 PMncy (CISA) has added [ 1 , 2 , 3 ] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog : CVE-2025-68645 (CVSS score of 8.8) Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability CVE-2020-7796 (CVSS score of 9.8) Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability C
newssecurityaffairs.comJul 10, 2026, 8:42 PM- Zimbra urges customers to patch critical web client XSS flawBleepingComputer
the Cybersecurity and Infrastructure Security Agency (CISA) ordered federal agencies to patch another Zimbra XSS flaw (CVE-2025-66376) exploited by hackers linked to the APT28 group (linked to Russia's military intelligence service) in attacks targeting Ukrainian government entities . In April, nonprofit security organization Shadowserver warned that
newswww.bleepingcomputer.comJul 10, 2026, 11:47 AM - 23rd March – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 23rd March, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Navia Benefit Solutions, a United States-based employee benefits administrator, has disclosed a breach affecting more than 2.6 million individuals after unauthorized access and potential data exfiltration occurred between December 22, 2025 and […]
vendorresearch.checkpoint.comMar 23, 2026, 1:38 PM A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. WorldLeaks ransomware group breached the City of Los Angels PolyShell flaw exposes Magento and Adobe Commerce […]
newssecurityaffairs.comMar 22, 2026, 12:48 AM- Russian APT targets Ukraine via Zimbra XSS flaw CVE-2025-66376Security Affairs
Russian APT exploits a critical XSS flaw in Zimbra, tracked as CVE-2025-66376, running scripts via HTML emails to target users in Ukraine. Russia-linked threat actor exploits a high-severity XSS vulnerability, tracked as CVE-2025-66376 (CVSS score of 7.2), in Zimbra Collaboration. Attackers exploited insufficiently sanitized HTML emails to run scripts when opened, targeting users in Ukraine. […]
newssecurityaffairs.comMar 19, 2026, 2:48 PM Insufficient sanitization of CSS content within HTML emails leads to inline script execution when the message is opened in a browser.
newswww.securityweek.comMar 19, 2026, 1:24 PM- U.S. CISA adds Microsoft SharePoint and Zimbra flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds SharePoint and Zimbra flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added ([1, 2]) SharePoint and Zimbra flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the flaws added to the catalog: The first vulnerability added to the catalog, tracked […]
newssecurityaffairs.comMar 18, 2026, 9:11 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-33370CVSS 6.1 · Medium
An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the Zimbra Briefcase feature due to insufficient s…
- CVE-2026-33368CVSS 6.1 · Medium
Zimbra Collaboration Suite (ZCS) 10.0 and 10.1 contains a reflected cross-site scripting (XSS) vulnerability in the Classic Webmail REST interface (/h/rest). The application fails…
- CVE-2025-48700CVSS 6.1 · Medium
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Classic UI allows attackers to exe…
- CVE-2024-45516CVSS 6.1 · Medium
An issue was discovered in Zimbra Collaboration (ZCS) 9.0.0 before Patch 43, 10.0.x before 10.0.12, 10.1.x before 10.1.4, and 8.8.15 before Patch 47. A Cross-Site Scripting (XSS)…
- CVE-2025-27915CVSS 5.4 · Medium
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the Classic Web Client due to insufficient…
- CVE-2024-45517CVSS 5.4 · Medium
An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A Cross-Site Scripting (XSS) vulnerability in the /h/rest endpoint of the Zimbra webmail and admin panel interf…