Junglewise Threat Intelligence

CVE-2025-66376: Synacor Zimbra Collaboration Suite stored XSS in Classic UI

CVE-2025-66376 · Severity: critical · CVSS 7.2 · Exploited in the wild · Published 2026-03-18

Executive brief

Zimbra Collaboration Suite is a widely used enterprise email and collaboration platform. A security flaw in its classic web interface allows attackers to send malicious emails that can execute unauthorized code in a user's browser. This could lead to the theft of login credentials, unauthorized access to sensitive emails, or the hijacking of user sessions.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the Classic UI of Zimbra Collaboration Suite (ZCS) versions 10.x. The flaw is rooted in the improper sanitization of Cascading Style Sheets (CSS) '@import' directives within HTML-formatted email messages. An unauthenticated remote attacker can exploit this by sending a specially crafted email to a target user. When the victim views the email in the Classic UI, the malicious CSS directive can trigger the execution of arbitrary JavaScript in the context of the user's session. This vulnerability has been observed being exploited in the wild. Patches are available in versions 10.0.18 and 10.1.13.

Affected products

  • Synacor Zimbra Collaboration Suite 10.0.0 before 10.0.18, 10.1.0 before 10.1.13

Timeline

  • 2026-01-05: disclosed: Initial CVE publication
  • 2026-03-18: kev added: CISA added the vulnerability to the Known Exploited Vulnerabilities (KEV) catalog
  • 2026-03-18: patched: Updated versions 10.0.18 and 10.1.13 confirmed as fixes

Related threats