LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-66376: Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 18, 2026
CVSS 7.2 · High⚠ Actively exploited (CISA KEV)
7.2
CVSS score
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 1, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-66376 to its Known Exploited Vulnerabilities catalog on Mar 18, 2026, with a federal patch deadline of Apr 1, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.

This vulnerability is a cross-site scripting flaw in Synacor Zimbra Collaboration Suite that affects the Classic UI. Attackers can exploit it by embedding malicious CSS directives in HTML emails. It matters because successful exploitation can allow arbitrary script execution in the context of a user's mailbox session.

How it works

The weakness is classified as CWE-79, improper neutralization of input during web page generation. In this case, the Classic UI fails to properly sanitize Cascading Style Sheets @import rules present in incoming email HTML.

An attacker can craft an email containing a specially formed @import directive. When the message is rendered in the vulnerable interface, the directive causes the browser to fetch and apply attacker-controlled styles that ultimately execute script code.

Am I affected? How to find it in your systems

Zimbra Collaboration Suite deployments that expose the Classic UI to email rendering are potentially impacted. Inventory all Zimbra instances in your environment and determine whether the Classic UI remains enabled.

Exact version applicability and affected configurations must be confirmed against the vendor advisory.

How to remediate

Apply the update or mitigation instructions published by the vendor for this issue. Follow any applicable CISA BOD 22-01 guidance if the deployment uses cloud services.

After patching, disable the Classic UI if it is not required for operations.

If you can't patch immediately

Until a patch can be applied, consider the following compensating measures:

If your data may have been exposed

Actively exploited cross-site scripting vulnerabilities can lead to account compromise and subsequent data exposure. Organizations should review authentication logs for suspicious sessions and consider running a free exposure scan of corporate email addresses against known breach datasets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSynacor · Zimbra Collaboration Suite (ZCS)
WeaknessCWE-79
CVSS base score7.2 (High)
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
PublishedJan 5, 2026
Added to CISA KEVMar 18, 2026
Federal patch deadlineApr 1, 2026
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities