Security Alert: Zimbra Collaboration Suite XSS Vulnerability Updates – March 2026
Zimbra has released security updates to address a vulnerability in the Zimbra Collaboration Suite (ZCS), identified as CVE-2025-66376. This vulnerability is a stored cross-site scripting (XSS) flaw affecting the Classic UI of ZCS.
Affected Systems
Security Risks
Successful exploitation of this vulnerability allows attackers to inject and execute malicious scripts within the Zimbra webmail interface, potentially resulting in session hijacking, theft of authentication credentials and sensitive email data, unauthorized access to mailboxes and organizational information.
Recommended Actions
The National Cyber Security Authority (NCSA) recommends users and system administrators to:
The released software version to upgrade to, are but are not limited to:
For further information and support, please contact the National Cyber Security Authority (NCSA) by email to rwcsirt@ncsa.gov.rw or call us on 9009.
References
19 March 2026
More updates
© 2026 National Cyber Security Authority