CISA added CVE-2025-66376 to its Known Exploited Vulnerabilities catalog after reports of active exploitation against Zimbra Collaboration Suite. The high-severity flaw affects the Classic UI and lets an unauthenticated remote attacker trigger stored/persistent XSS by sending malicious HTML email that abuses the CSS @import directive, potentially exposing sensitive information and creating a path to further compromise.
The vulnerability affects Zimbra Collaboration Suite versions earlier than 10.0.18 and 10.1.13. Synacor patched the issue in November 2025, and Zimbra security advisories list the fixed releases; organizations running vulnerable versions have been urged to upgrade immediately to 10.0.18, 10.1.13, or later because the flaw is already being exploited in the wild.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
CISA added CVE-2025-66376 to its Known Exploited Vulnerabilities catalog after determining the Zimbra Collaboration Suite flaw was being actively exploited. The vulnerability enables unauthenticated persistent XSS and could lead to sensitive information disclosure or possible remote code execution.
Synacor patched CVE-2025-66376, a high-severity stored XSS vulnerability in the Zimbra Classic UI, in November 2025. The flaw affects versions earlier than 10.0.18 and 10.1.13 and can be triggered via malicious HTML emails abusing the CSS @import directive.
Threat actors attributed with medium confidence to Russian groups including TA488, CL-STA-1114, and APT28 have exploited the Zimbra stored XSS flaw since at least July 2025 in a campaign dubbed Operation GhostMail. The activity targeted Western government, defense, transportation, financial organizations, and Ukraine, enabling mailbox compromise and theft of session tokens, passwords, 2FA scratch codes, and mailbox data.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.