CVE-2025-66376: Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability
Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.
How it works
The weakness is classified as CWE-79, improper neutralization of input during web page generation. In this case, the Classic UI fails to properly sanitize Cascading Style Sheets @import rules present in incoming email HTML.
An attacker can craft an email containing a specially formed @import directive. When the message is rendered in the vulnerable interface, the directive causes the browser to fetch and apply attacker-controlled styles that ultimately execute script code.
Am I affected? How to find it in your systems
Zimbra Collaboration Suite deployments that expose the Classic UI to email rendering are potentially impacted. Inventory all Zimbra instances in your environment and determine whether the Classic UI remains enabled.
- Review server configurations and user preferences for Classic UI usage.
- Examine email processing logs for unusual CSS import activity or unexpected external resource fetches originating from mailbox sessions.
Exact version applicability and affected configurations must be confirmed against the vendor advisory.
How to remediate
Apply the update or mitigation instructions published by the vendor for this issue. Follow any applicable CISA BOD 22-01 guidance if the deployment uses cloud services.
After patching, disable the Classic UI if it is not required for operations.
If you can't patch immediately
Until a patch can be applied, consider the following compensating measures:
- Segment the Zimbra deployment to limit exposure from untrusted email sources.
- Disable the Classic UI where feasible.
- Monitor mailbox access logs for anomalous behavior consistent with script injection attempts.
- If mitigations are unavailable, discontinue use of the affected product as recommended by CISA.
If your data may have been exposed
Actively exploited cross-site scripting vulnerabilities can lead to account compromise and subsequent data exposure. Organizations should review authentication logs for suspicious sessions and consider running a free exposure scan of corporate email addresses against known breach datasets.
AICompiled with AI assistance from public sources and published under our editorial standards.
Details
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:NReferences
- wiki.zimbra.com/wiki/Security_Center
- wiki.zimbra.com/wiki/Zimbra_Releases/10.0.18#Security_Fixes
- wiki.zimbra.com/wiki/Zimbra_Releases/10.1.13#Security_Fixes
- wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy
- wiki.zimbra.com/wiki/Zimbra_Security_Advisories
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-66376