Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»CISA orders feds to patch Zimbra XSS flaw exploited in attacks
    Cybersecurity

    CISA orders feds to patch Zimbra XSS flaw exploited in attacks

    adminBy adminMarch 19, 2026No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Email
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Email

    CISA has ordered U.S. government agencies to secure their servers against an actively exploited vulnerability in the Zimbra Collaboration Suite (ZCS).

    Zimbra is a very popular email and collaboration software suite used by hundreds of millions of people worldwide, including thousands of businesses and hundreds of government agencies.

    Tracked as CVE-2025-66376 and patched in early November, this high-severity security flaw stems from a stored cross-site scripting (XSS) weakness in the Classic UI that remote unauthenticated attackers could exploit by abusing Cascading Style Sheets (CSS) @import directives in email HTML.

    While Synacor (the company behind Zimbra) didn’t share any details on the impact of a successful CVE-2025-66376 attack, it can likely be exploited to execute arbitrary JavaScript via malicious HTML-based emails, potentially allowing attackers to hijack user sessions and steal sensitive data within the compromised Zimbra environment.

    CISA added it to its catalog of vulnerabilities exploited in the wild on Wednesday and gave Federal Civilian Executive Branch (FCEB) agencies two weeks to secure their servers by April 1st, as mandated by the Binding Operational Directive (BOD) 22-01 issued in November 2021.

    Although BOD 22-01 applies only to federal agencies, the U.S. cybersecurity agency encouraged all organizations, including those in the private sector, to patch this actively exploited flaw as soon as possible.

    “Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable,” CISA warned. “These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.”

    Zimbra servers under attack

    Zimbra security flaws are frequently targeted in attacks and have been exploited to breach thousands of vulnerable email servers worldwide in recent years.

    For instance, as early as June 2022, Zimbra auth-bypass and remote code execution bugs were abused to breach more than 1,000 servers.

    Starting in September 2022, hackers exploited a zero-day vulnerability in Zimbra Collaboration Suite, breaching nearly 900 servers within two months after gaining remote code execution on compromised instances.

    The Russian state-backed Winter Vivern hacking group also used reflected XSS exploits to breach the Zimbra webmail portals of NATO-aligned governments and the mailboxes of government officials, military personnel, and diplomats.

    More recently, threat actors exploited another Zimbra XSS vulnerability (CVE-2025-27915) in zero-day attacks to execute arbitrary JavaScript code, enabling them to set email filters that redirect messages to attacker-controlled servers.


    tines

    Malware is getting smarter. The Red Report 2026 reveals how new threats use math to detect sandboxes and hide in plain sight.

    Download our analysis of 1.1 million malicious samples to uncover the top 10 techniques and see if your security stack is blinded.

    attacks CISA Exploited feds Flaw Orders Patch XSS Zimbra
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleSave $450 on the Segway Max G3 Electric Scooter
    Next Article I tried Amazon Alexa+, and I’ve never been this excited about a smart home assistant before
    admin
    • Website

    Related Posts

    Rapid7 enhances Exposure Command with runtime validation and DSPM for risk analysis

    March 21, 2026

    DOJ confirms seizure of domains linked to Iran-backed threat actor

    March 21, 2026

    Oracle pushes emergency fix for critical Identity Manager RCE flaw

    March 21, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    Rapid7 enhances Exposure Command with runtime validation and DSPM for risk analysis

    March 21, 2026

    This mini-CRT cyberdeck is the coolest Raspberry Pi 5 project I’ve ever seen

    March 21, 2026

    DOJ confirms seizure of domains linked to Iran-backed threat actor

    March 21, 2026

    Your Galaxy S26 can now double as a webcam for your PC

    March 21, 2026
    Categories
    • Blogging (43)
    • Cybersecurity (890)
    • Privacy & Online Earning (127)
    • SEO & Digital Marketing (549)
    • Tech Tools & Mobile / Apps (1,076)
    • WiFi / Internet & Networking (153)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    Rapid7 enhances Exposure Command with runtime validation and DSPM for risk analysis

    March 21, 2026

    This mini-CRT cyberdeck is the coolest Raspberry Pi 5 project I’ve ever seen

    March 21, 2026

    DOJ confirms seizure of domains linked to Iran-backed threat actor

    March 21, 2026
    Most Popular
    • Rapid7 enhances Exposure Command with runtime validation and DSPM for risk analysis
    • This mini-CRT cyberdeck is the coolest Raspberry Pi 5 project I’ve ever seen
    • DOJ confirms seizure of domains linked to Iran-backed threat actor
    • Your Galaxy S26 can now double as a webcam for your PC
    • Oracle pushes emergency fix for critical Identity Manager RCE flaw
    • Google Business Profile tests AI-generated replies to reviews
    • You can still get a free gift card with your Samsung Galaxy S26!
    • Eclypsium Raises $25 Million for Device Supply Chain Security
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.