CVE-2025-66376: Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability
Medium severity, CVSS 6.1. Actively exploited: in CISA KEV since 2026-03-18. EPSS: 20.2% chance of exploitation in the next 30 days.
Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.
Affected products
- Synacor Zimbra Collaboration Suite: from 10.0.0, before 10.0.18 (fixed in 10.0.18); from 10.1.0, before 10.1.13 (fixed in 10.1.13)
Published 2026-01-05. Last modified 2026-10-07.