Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-07-24 ยท updated: 2026-07-24 ยท tags: [cve, zero-day, kev, xss, email, government] ยท confidence: high ยท severity: not-rated ยท affected_sectors: [government, technology] ยท au_impact: true

CVE-2025-66376 โ€” Zimbra Classic UI Stored XSS

CVE-2025-66376 is a stored cross-site scripting (XSS) vulnerability in Zimbra's Classic UI that has been exploited in the wild as a zero-day by a Russian state-sponsored espionage group since at least July 2025.

Details

Field Detail
CVE CVE-2025-66376
Type Stored XSS (view-based exploit)
Component Zimbra Classic UI / CSS @import handling
Exploitation Triggers when a user opens a crafted HTML email
Discovered Exploited since ~July 2025
Advisory Aa26 204A (CISA/NSA/ACSC joint advisory)

Impact

The view-based exploit activates when a recipient opens a maliciously crafted HTML email that abuses CSS @import handling. Successful exploitation enables the attacker to:

  • Exfiltrate 90 days of email from the victim's mailbox
  • Extract the full directory (Global Address List)
  • Steal saved browser passwords from the Zimbra session
  • Capture 2FA recovery codes, enabling persistent access
  • Full mailbox compromise of Western government and commercial systems

Advisory & Attribution

A joint advisory โ€” Aa26 204A โ€” was published July 23, 2026 by: - CISA (US Cybersecurity and Infrastructure Security Agency) - NSA (National Security Agency) - ACSC (Australian Cyber Security Centre) - Palo Alto Networks Unit 42 - Proofpoint

Attribution: A Russian state-supported espionage group (specific group not named in public advisory).

Related Pages