CVE-2025-66376
Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.
- Published Jan 5, 2026
- CVSS 6.1 medium
- 20.2% chance of exploitation in the next 30 days (EPSS)
- In CISA's Known Exploited Vulnerabilities catalog
- A fix is available
Affected software
In the news
- Russian state-supported cyber actors conduct phishing campaign targeting users of Zimbra Collaboration Suite Australian Cyber Security Centre ·