Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2498+ Articles
161+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Zimbra Urges Customers to Patch Critical Web Client XSS Flaw Exploited in the Wild
Zimbra Urges Customers to Patch Critical Web Client XSS Flaw Exploited in the Wild
NEWS

Zimbra Urges Customers to Patch Critical Web Client XSS Flaw Exploited in the Wild

CVE-2025-27915, a stored XSS vulnerability in Zimbra's Classic Web Client, was exploited as a zero-day before public disclosure. Attackers used malicious...

Dylan H.

News Desk

July 10, 2026
3 min read

Zimbra is urging all customers running its Collaboration Suite to apply security patches immediately after a critical stored cross-site scripting (XSS) vulnerability was discovered being actively exploited in targeted attacks. The flaw, tracked as CVE-2025-27915 with a CVSS score of 5.4, allowed attackers to hijack authenticated Zimbra sessions through a cleverly crafted calendar file.

The Vulnerability

The flaw resides in the Zimbra Collaboration Suite (ZCS) Classic Web Client and stems from insufficient sanitization of HTML content embedded in ICS calendar files. Attackers craft malicious .ics entries that deliver JavaScript via an ontoggle event handler inside a <details> HTML tag.

When a targeted user opens the malicious calendar invite through the Classic UI, the embedded script executes within their authenticated session, enabling:

  • Session hijacking — stealing session tokens for persistent access
  • Email filter manipulation — creating silent redirect rules to exfiltrate incoming messages
  • Data exfiltration — access to emails, contacts, shared folders, and credentials stored in the webmail client

Exploited as a Zero-Day

The vulnerability was exploited in the wild before public disclosure, making it a zero-day at time of attack. Threat actors spoofed communications from Libya's Office of Protocol — the official diplomatic protocol office of the Libyan Navy — to target the Brazilian military.

The tactics, techniques, and procedures observed bear similarities to UNC1151, also known as the Ghostwriter APT — a threat group with Belarus state alignment known for information operations and credential theft. Researchers stopped short of definitive attribution.

CISA Response

CISA added CVE-2025-27915 to its Known Exploited Vulnerabilities (KEV) catalog and ordered Federal Civilian Executive Branch (FCEB) agencies to apply patches by April 1, 2026 under Binding Operational Directive 22-01.

Affected Versions and Patches

VersionFix Available In
ZCS 9.0.0Patch 44 or later
ZCS 10.0.xVersion 10.0.13 or later
ZCS 10.1.xVersion 10.1.5 or later

All patches were made available in January 2025 or later. Organizations still running unpatched versions have been exposed for an extended period.

Mitigations

For organizations that cannot immediately patch, Zimbra recommends:

  1. Disable the Classic Web Client and force users to the Modern Web Client, which does not have the same ICS rendering path
  2. Deploy WAF rules to strip suspicious HTML attributes (specifically ontoggle handlers) from ICS attachments before they reach end-users
  3. Monitor for anomalous email filter changes that could indicate session hijacking

Given that Zimbra is widely deployed in government agencies, military organizations, and enterprises globally, organizations should treat this as a high-priority patch regardless of the moderate CVSS score — active exploitation by a likely state-aligned actor significantly elevates real-world risk.

#Zimbra#XSS#cve-2025-27915#cisa-kev#Zero-Day#email-security#Patch

Related Articles

Russian Laundry Bear Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

A Russian state-sponsored espionage group spent months silently reading Western mailboxes through a zero-click XSS flaw in Zimbra's webmail client —...

5 min read

Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets

State-sponsored threat group 'Laundry Bear' is weaponizing a Zimbra zero-day using half-click phishing emails that trigger exploitation simply by opening or previewing a message.

3 min read

Russian APT 'Laundry Bear' Exploited Zimbra Zero-Day with Half-Click Email Attack

Russia-backed Laundry Bear (Void Blizzard/TA488) exploited CVE-2025-66376 — a stored XSS flaw in Zimbra's Classic UI — to compromise US, Ukrainian, and NATO targets. The 'half-click' attack triggers just by opening an email, bypasses MFA, and plants a persistent backdoor credential.

6 min read
Back to all News