Skip to main content

CVE detail

CVE-2025-66376

Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.

CVSS 7.2 · HighBuzz score 75.0KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 75.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
30.0
20 evidence mentions in the snapshot
Diversity score
20.0
11 sources across 3 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
13
within the 30d window
Peak daily
5
highest bucket

Evidence

Source links by recency

Newest mentions first
20 source links · newest first
  • inancial, hospitality, and aerospace sectors. The activity, which began on July 22, 2026, involves the weaponization of CVE-2026-42897 (CVSS score: 8.1), a cross-site scripting (XSS) vulnerability in OWA. It was flagged by Microsoft as having been exploited in attacks as far back as May 2026. Enterprise security company Proofpoint has attributed the ac

    newsthehackernews.comJul 30, 2026, 7:40 AM
  • 27th July – Threat Intelligence ReportCheck Point Research

    ,000 artifacts and a campaign that recorded over 77,000 requests. VULNERABILITIES AND PATCHES Check Point has addressed CVE-2026-16232, an authentication bypass vulnerability in SmartConsole that is under active exploitation, affecting a handful of customers. The flaw allows remote attackers to bypass authentication and gain administrative access to Ch

    vendorresearch.checkpoint.comJul 27, 2026, 4:00 PM
  • products, including a critical flaw that has come under active exploitation in the wild. The security flaw, tracked as CVE-2026-16232 (CVSS score: 9.3), is an authentication bypass affecting the Check Point SmartConsole login process that allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with ful

    newsthehackernews.comJul 27, 2026, 2:10 PM
  • that can be chained together to achieve persistent root-level access. By exploiting an arbitrary file disclosure flaw (CVE-2025-40948), an attacker can gather sensitive system intelligence to facilitate a subsequent privilege escalation via command injection (CVE-2025-40947). The compromise is then cemented using a third vulnerability (CVE-2025-40949)

    newswww.securityweek.comJul 24, 2026, 2:20 PM
  • get into police employee accounts. Attackers weaponize Zimbra XSS vulnerability The attackers’ latest campaign targets CVE-2025-66376, a cross-site scripting (XSS) vulnerability in the Zimbra web-based email and collaboration suite that was patched in November 2025. The advisory notes the group kept using the exploit even after the fix came out, meani

    newswww.helpnetsecurity.comJul 24, 2026, 12:09 PM
  • ern government and commercial organizations since at least July 2025. That campaign uses a “half-click” exploit abusing CVE-2025-66376 to deliver malicious JavaScript called ZimReaper, which can harvest email communications without requiring the victim to click anything beyond opening a malicious email in a vulnerable webmail client. The U.S. governmen

    newssecurityaffairs.comJul 24, 2026, 9:54 AM
  • Bear (aka Void Blizzard) is targeting organizations using unpatched Zimbra Collaboration servers. The attackers exploit CVE-2025-66376 , an XSS flaw that allows malicious JavaScript embedded in HTML emails to run automatically when viewed, enabling account theft without user interaction. The vulnerability was exploited as a zero-day before being patche

    newssecurityaffairs.comJul 24, 2026, 8:31 AM
  • has been targeting ZCS customers since July 2025. Laundry Bear actors used a zero-day vulnerability in ZCS , tracked as CVE-2025-66376, in a phishing campaign that featured what experts describe as a "half-click exploit" to breach Zimbra webmail servers. "Unlike traditional phishing campaigns that persuade a user into taking an action, such as clicking

    newswww.darkreading.comJul 23, 2026, 9:23 PM
  • ation, energy, law enforcement, media, non-governmental organizations, and technology. The attackers exploit the Zimbra CVE-2025-66376 flaw, a cross-site scripting (XSS) vulnerability affecting Zimbra Collaboration Suite's Classic UI. The flaw allows JavaScript embedded in specially crafted HTML emails to execute automatically when a victim views the m

    newswww.bleepingcomputer.comJul 23, 2026, 4:49 PM
  • on the covert acquisition of email data,” according to the joint security alert. The Russians’ latest campaign targets CVE-2025-66376, a cross-site scripting (XSS) vulnerability in the Zimbra web-based email and collaboration suite that was patched in November 2025 – but Moscow's attackers began exploiting it long before then. This type of vulnerabili

    newswww.theregister.comJul 23, 2026, 4:47 PM
  • ry Bear, also known as Void Blizzard and UAC-0190 . The Laundry Bear campaign exploits a zero-day vulnerability in ZCS (CVE-2025-66376) which was publicly disclosed in November 2025 and uses a zero-click exploit coined “beehive” to steal emails and other sensitive data. Unlike traditional phishing campaigns which require a user to be socially engineere

    newswww.infosecurity-magazine.comJul 23, 2026, 3:50 PM
  • rst exploited and continues to be successfully exploited. The vulnerability, Common Vulnerabilities and Exposures (CVE) CVE-2025-66376 , was patched in November 2025. This demonstrates LAUNDRY BEAR’s intent and ability to deploy increasingly sophisticated technical capabilities. Unlike traditional phishing campaigns that persuade a user into taking an

    governmentwww.cisa.govJul 23, 2026, 12:00 PM
  • en leak session cookies. In 2025, an XSS vulnerability in the calendar import feature of the Zimbra Classic Web Client (CVE-2025-27915) was exploited in attacks targeting Brazilian military personnel . Many other Zimbra vulnerabilities have been exploited over the years, sometimes as zero-days, especially by Russian state-sponsored APT groups, such as

    newswww.csoonline.comJul 22, 2026, 8:26 PM
  • ncy (CISA) has added [ 1 , 2 , 3 ] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog : CVE-2025-68645 (CVSS score of 8.8) Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability CVE-2020-7796 (CVSS score of 9.8) Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability C

    newssecurityaffairs.comJul 10, 2026, 8:42 PM
  • the Cybersecurity and Infrastructure Security Agency (CISA) ordered federal agencies to patch another Zimbra XSS flaw (CVE-2025-66376) exploited by hackers linked to the APT28 group (linked to Russia's military intelligence service) in attacks targeting Ukrainian government entities . In April, nonprofit security organization Shadowserver warned that

    newswww.bleepingcomputer.comJul 10, 2026, 11:47 AM
  • 23rd March – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 23rd March, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Navia Benefit Solutions, a United States-based employee benefits administrator, has disclosed a breach affecting more than 2.6 million individuals after unauthorized access and potential data exfiltration occurred between December 22, 2025 and […]

    vendorresearch.checkpoint.comMar 23, 2026, 1:38 PM
  • A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. WorldLeaks ransomware group breached the City of Los Angels PolyShell flaw exposes Magento and Adobe Commerce […]

    newssecurityaffairs.comMar 22, 2026, 12:48 AM
  • Russian APT exploits a critical XSS flaw in Zimbra, tracked as CVE-2025-66376, running scripts via HTML emails to target users in Ukraine. Russia-linked threat actor exploits a high-severity XSS vulnerability, tracked as CVE-2025-66376 (CVSS score of 7.2), in Zimbra Collaboration. Attackers exploited insufficiently sanitized HTML emails to run scripts when opened, targeting users in Ukraine. […]

    newssecurityaffairs.comMar 19, 2026, 2:48 PM
  • Insufficient sanitization of CSS content within HTML emails leads to inline script execution when the message is opened in a browser.

    newswww.securityweek.comMar 19, 2026, 1:24 PM
  • U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds SharePoint and Zimbra flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added ([1, 2]) SharePoint and Zimbra flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the flaws added to the catalog: The first vulnerability added to the catalog, tracked […]

    newssecurityaffairs.comMar 18, 2026, 9:11 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence