
CISA has directed U.S. government agencies to protect their systems from an actively used vulnerability in Zimbra.
Zimbra is a widely used email and groupware platform with a large global user base, including many businesses and government entities.
Identified as CVE-2025-66376 and fixed in early November, this serious security issue is a stored XSS vulnerability in the Classic UI. Remote, unauthenticated attackers can exploit it by manipulating CSS @import directives in HTML emails.
Synacor has not provided details on the impact of successful exploitation of CVE-2025-66376, but it likely allows the execution of arbitrary JavaScript through malicious HTML emails. This could enable attackers to take over user sessions and steal sensitive data from compromised Zimbra accounts.
CISA added the vulnerability to its list of actively exploited vulnerabilities on Wednesday, giving federal agencies until April 1st to secure their servers. This deadline is in line with Binding Operational Directive (BOD) 22-01, issued in November 2021.
While BOD 22-01 is specific to federal agencies, CISA urges all organizations, including private sector businesses, to patch this actively exploited vulnerability as quickly as possible.
“Apply the vendor’s recommended mitigations, follow BOD 22-01 guidelines for cloud services, or stop using the product if no mitigations are available,” CISA advised. “These vulnerabilities are commonly used by malicious actors and pose significant risks to federal systems.”
Zimbra vulnerabilities are frequently targeted and have been used in the past to compromise thousands of email servers globally.
For example, in June 2022, Zimbra authentication bypass and remote code execution flaws were exploited to compromise over 1,000 servers.
Beginning in September 2022, attackers exploited a Zimbra zero-day, compromising almost 900 servers in two months after achieving remote code execution.
The Russian Winter Vivern group has also used reflected XSS exploits to breach Zimbra webmail portals belonging to NATO-aligned governments and access the mailboxes of government officials, military personnel, and diplomats.
More recently, attackers exploited another Zimbra XSS vulnerability (CVE-2025-27915) as a zero-day, executing arbitrary JavaScript code to set up email filters that redirected messages to attacker-controlled servers.
#active #address #agencies #attacks #cisa #exploited #federal #fix #hole #mandates #must #news #patch #security #zimbra — News
© Bulletproof Servers. All rights reserved.