CVE-2025-66376 – High-Severity Stored XSS in Synacor Zimbra Collaboration Suite (ZCS)

Key takeaways

  • High severity (MITRE CVSS 7.2) stored cross‑site scripting in Zimbra Classic UI.
  • Actively exploited by APT28 against Ukrainian government agencies.
  • Added to the CISA KEV catalog on 2026‑03‑18.
  • Affects ZCS 10 < 10.0.18 and 10.1 < 10.1.13.
  • Immediate patch or mitigation required.

Overview

A stored cross‑site scripting (XSS) flaw was discovered in the Classic UI of the Zimbra Collaboration Suite (ZCS). The vulnerability (identified as CVE-2025-66376) allows an attacker to embed a malicious CSS @import directive inside an HTML email. When the email is rendered, the imported stylesheet executes arbitrary JavaScript in the victim’s browser session.

The flaw is being actively weaponized by the Russian‑linked APT28 (also known as Fancy Bear) to target Ukrainian government agencies, delivering a browser‑resident stealer that exfiltrates credentials and session tokens via DNS and HTTPS. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on 2026‑03‑18, confirming real‑world exploitation.


Technical Details

  • Vulnerability type: Stored XSS (CWE‑79) in the Classic UI email renderer.
  • Attack vector: Injection of a CSS @import directive within an HTML email body. The malicious stylesheet loads and executes attacker‑controlled JavaScript when the email is opened.
  • Impact: An attacker can steal authentication cookies, capture 2FA codes, read mailbox contents, and pivot to internal web applications.
  • CVSS scores:
    • MITRE: CVSS 7.2 (High) – AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
    • NVD: CVSS 6.1 (Medium) – AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
  • Exploitation evidence: Multiple threat‑intel reports from March 18‑21 2026 document active exploitation, including sample phishing emails and network‑level exfiltration of DNS/HTTPS traffic.

Severity & Impact

The combination of a network‑reachable vector, no authentication required, and the ability to run arbitrary JavaScript in a privileged webmail session makes this flaw high‑severity. Successful exploitation can lead to credential theft, session hijacking, and persistent surveillance of targeted users. The inclusion in the CISA KEV catalog underscores the urgent risk to organizations that still run vulnerable ZCS versions.


Affected Products

  • Synacor Zimbra Collaboration Suite (ZCS) 10 Classic UI versions earlier than 10.0.18 and earlier than 10.1.13.

For the complete list of affected versions and CPE identifiers, see the official CVE page: https://vulnsocial.com/cve/CVE-2025-66376.


Actionable Insights – What to Monitor

  • Email content: Scan inbound HTML emails for <style> tags or @import statements that reference external URLs.
  • Network traffic: Look for anomalous DNS queries or HTTPS connections to domains that do not belong to your organization, especially shortly after an email is opened.
  • Browser activity: Detect unexpected JavaScript execution or DOM modifications in the Zimbra web client.
  • Threat intel: Subscribe to CISA KEV updates and monitor for indicators related to APT28 (e.g., known command‑and‑control domains, payload hashes).
  • Log correlation: Correlate mail server logs with web proxy logs to identify users who opened suspicious messages.

Remediation & Mitigation

  1. Patch – Upgrade ZCS to 10.0.18 or 10.1.13 (or any later release). These versions remove the vulnerable CSS handling.
  2. Disable Classic UI – If immediate patching is not possible, disable the Classic UI and force users to the Modern UI, which does not process the vulnerable CSS.
  3. Sanitize inbound email – Configure the mail gateway to strip <style> tags and any @import directives from HTML messages.
  4. Deploy a WAF rule – Block responses that contain <style> elements with @import URLs or any inline JavaScript injected into email bodies.
  5. User awareness – Educate users to avoid opening unexpected HTML emails, especially from unknown senders, and to report suspicious messages.
  6. Detect IOCs – Implement SIEM alerts for the following indicators:
    • DNS queries to newly‑registered or low‑reputation domains shortly after email receipt.
    • HTTPS traffic to external C2 domains matching known APT28 patterns.
    • Presence of the JavaScript payload “GhostMail” or similar stealer code in browser memory.

Apply the patch as soon as possible; mitigation steps 2‑6 provide defense‑in‑depth until the upgrade is completed.


Bottom line

CVE-2025-66376 is a high‑severity stored XSS flaw in Zimbra Classic UI that is actively exploited by APT28. Organizations running vulnerable ZCS versions must patch immediately or apply the listed mitigations to block the attack chain.


References

  • https://wiki.zimbra.com/wiki/Security_Center – Zimbra Security Center.
  • https://wiki.zimbra.com/wiki/Zimbra_Releases/10.0.18#Security_Fixes – Patch notes for ZCS 10.0.18.
  • https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.13#Security_Fixes – Patch notes for ZCS 10.1.13.
  • https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy – Responsible disclosure policy.
  • https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories – Security advisories archive.
  • https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-66376 – CISA KEV entry for CVE-2025-66376.
  • https://vulnsocial.com/cve/CVE-2025-66376 – Live threat intelligence and timeline.

#CVE #CVE202566376 #Zimbra #Synacor #CISAKEV #XSS #APT28