PT-2026-1290 · Zimbra · Zimbra Collaboration
CVE-2025-66376
·
Published
2026-01-05
·
Updated
2026-08-25
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Zimbra Collaboration Suite versions prior to 10.0.18
Zimbra Collaboration Suite versions prior to 10.1.13
Description
A stored cross-site scripting (XSS) flaw exists in the Classic UI of the software. The issue occurs when the HTML sanitizer fails to block malicious JavaScript payloads that are split across CSS
@import directives and HTML comments within an HTML email message. This allows a remote attacker to execute arbitrary scripts in the user's authenticated session simply by having the user preview or open a specially crafted email, requiring no further interaction (zero-click).This flaw has been actively exploited by state-sponsored actors, including APT28 and LAUNDRY BEAR (also known as Void Blizzard), targeting government agencies, defense contractors, and commercial organizations. The exploitation chain can lead to session hijacking, theft of session tokens, and unauthorized access to mailbox data. In some cases, this has been used to enable IMAP access via the creation of an Application Passcode named
ZimbraWeb, bypassing multi-factor authentication (MFA) and allowing the exfiltration of up to 90 days of mailbox content. The stolen data is transmitted using a custom tool called Ulej to a collection system named Flowerbed via DNS and HTTPS.Recommendations
Update Zimbra Collaboration Suite to version 10.0.18 or later.
Update Zimbra Collaboration Suite to version 10.1.13 or later.
Revoke all existing Application Passcodes and 2FA scratch codes to remove persistence established by attackers.
Audit access logs for anomalous authentication patterns and monitor for unexpected processes or scheduled tasks.
Exploit
Fix
RCE
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zimbra Collaboration