peter bassill · operator
$ cve CVE-2025-66376 JSON

CVE-2025-66376 KEV

7.2
HIGH · CVSS 3.1 · EPSS 19.6% (pctl 97)

Patch first

On CISA KEV — known exploited in the wild, due 2026-04-01.

Description

Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.

Scoring

CVSS7.2 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
EPSS19.56% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-79
On CISA KEVyes — remediate by 2026-04-01
Public exploitnone known
Published2026-01-05
Last modified2026-06-17

CISA KEV

NameSynacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability
Added2026-03-18
Due2026-04-01
Vendor / productSynacor / Zimbra Collaboration Suite (ZCS)
Ransomware usenone reported

Affected (1)

VendorProduct
synacorzimbra collaboration suite

References

→ the Explorer  ·  watch your stack  ·  NVD