Zimbra Urges Customers to Patch Critical Web Client XSS Flaw
Zimbra, a popular email and collaboration software suite, has released a patch for a critical vulnerability affecting the Classic Web Client used to access the Zimbra Collaboration suite. The vulnerability, which has yet to receive a CVE ID, is a stored cross-site scripting (XSS) security flaw that could allow attackers to execute malicious code when a specially crafted email is opened.
According to Zimbra, the vulnerability only impacts users of the Classic Web Client, and customers are urged to upgrade to ZCS v10.1.19 as soon as possible to keep their environment secure. The company warned that successful exploitation of the vulnerability could help threat actors steal session data, account settings, or mailbox information.
Reported by Google's Threat Analysis Group
The vulnerability was reported by Google's Threat Analysis Group, which frequently flags zero-day exploits deployed by state-backed hacking groups in cyberattacks targeting high-risk individuals, including opposition politicians, dissidents, and journalists.
Zimbra security issues have been frequently exploited in attacks by Russian state-sponsored hackers in recent years to compromise thousands of vulnerable servers. For instance, the Russian-sponsored Winter Vivern hacking group used a reflected XSS exploit to breach Zimbra webmail portals in February 2023, stealing emails from NATO-aligned organizations and individuals, including government officials, military personnel, and diplomats.
Previous Exploitation by Russian State Hackers
In October 2024, U.S. and U.K. cyber agencies warned that APT29 (also known as Midnight Blizzard and Cozy Bear) hackers working for Russia's Foreign Intelligence Service (SVR) were targeting vulnerable Zimbra servers at a mass scale using an exploit that targeted a flaw previously abused to steal email account credentials. More recently, in March, the Cybersecurity and Infrastructure Security Agency (CISA) ordered federal agencies to patch another Zimbra XSS flaw (CVE-2025-66376) exploited by hackers linked to the APT28 group (linked to Russia's military intelligence service) in attacks targeting Ukrainian government entities.
In April, nonprofit security organization Shadowserver warned that over 10,500 Zimbra Collaboration Suite (ZCS) instances exposed online were still vulnerable to ongoing attacks exploiting another cross-site scripting (XSS) security flaw (tracked as CVE-2025-48700). This highlights the importance of patching vulnerabilities and testing security measures to prevent exploitation by attackers.
Conclusion
The Zimbra web client XSS vulnerability is a critical flaw that could allow attackers to steal sensitive information. Customers are urged to upgrade to ZCS v10.1.19 as soon as possible to keep their environment secure. The vulnerability is a reminder of the importance of patching vulnerabilities and testing security measures to prevent exploitation by attackers.
As stated in the Picus whitepaper, Test every layer before attackers do. Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen. The whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
For more information on the vulnerability and how to patch it, customers can visit the Zimbra website. It is essential to stay informed about the latest security vulnerabilities and patches to prevent exploitation by attackers.
Source: BleepingComputer