CISA BOD 22-01 Zimbra patch order
Public Sector Action
Summary
Hide ▲
Show ▼
CISA ordered Federal Civilian Executive Branch agencies to secure Zimbra Collaboration Suite (ZCS) servers against CVE-2025-66376, an actively exploited flaw that could enable session hijacking and data theft. The directive gave agencies two weeks to act, with a deadline of April 1st, because exposed mail systems remain a live attack surface. CISA also urged other organizations to patch or mitigate the issue as soon as possible.
Related Happenings
CISA KEV directive for Joomla extension flaws
Public Sector Action
H score36
First: 13.07.2026 18:20
Last: 13.07.2026 18:20
Sources 1
About this happening:
CISA added the Joomla extension flaws to the KEV catalog and ordered federal agencies to apply updates or mitigations within three days, tightening remediation tim...
CISA KEV directive for Joomla extension flaws
Public Sector ActionAbout this happening: CISA added the Joomla extension flaws to the KEV catalog and ordered federal agencies to apply updates or mitigations within three days, tightening remediation tim...
Zimbra Classic Web Client stored XSS cross-site scripting flaw
Vulnerability
H score26
First: 11.07.2026 09:45
Last: 11.07.2026 09:45
Sources 1
About this happening:
Zimbra fixed a critical stored XSS flaw in the Classic Web Client that could let a specially crafted email run malicious code in a user's session. The weakness cou...
Zimbra Classic Web Client stored XSS cross-site scripting flaw
VulnerabilityAbout this happening: Zimbra fixed a critical stored XSS flaw in the Classic Web Client that could let a specially crafted email run malicious code in a user's session. The weakness cou...
Zimbra Classic Web Client stored XSS security update
Security Patch Release
H score32
First: 10.07.2026 14:47
Last: 10.07.2026 14:47
Sources 1
About this happening:
Zimbra released ZCS v10.1.19 to patch a stored XSS flaw in the Classic Web Client, narrowing exposure for users of that interface. The bug could be triggered through *...
Zimbra Classic Web Client stored XSS security update
Security Patch ReleaseAbout this happening: Zimbra released ZCS v10.1.19 to patch a stored XSS flaw in the Classic Web Client, narrowing exposure for users of that interface. The bug could be triggered through *...
Zimbra Classic Web Client stored XSS cross-site scripting flaw
Vulnerability
H score22
First: 10.07.2026 14:47
Last: 10.07.2026 14:47
Sources 1
About this happening:
Zimbra's Classic Web Client stored cross-site scripting (XSS) flaw was patched in Zimbra 10.1.19, closing a path that could expose session data, account settings...
Zimbra Classic Web Client stored XSS cross-site scripting flaw
VulnerabilityAbout this happening: Zimbra's Classic Web Client stored cross-site scripting (XSS) flaw was patched in Zimbra 10.1.19, closing a path that could expose session data, account settings...
CISA KEV remediation order for CVE-2026-48907
Public Sector Action
H score89
First: 17.06.2026 08:50
Last: 17.06.2026 08:50
Sources 1
About this happening:
CISA added CVE-2026-48907 to the KEV catalog and ordered FCEB agencies to apply fixes by June 19, 2026, forcing federal remediation of an actively exploited Jo...
CISA KEV remediation order for CVE-2026-48907
Public Sector ActionAbout this happening: CISA added CVE-2026-48907 to the KEV catalog and ordered FCEB agencies to apply fixes by June 19, 2026, forcing federal remediation of an actively exploited Jo...
Timeline
-
18.03.2026 21:57 2 articles · 3mo ago
CISA orders federal agencies to patch Zimbra CVE-2025-66376
Legal Policy Action UpdateCISA ordered U.S. federal civilian agencies to secure Zimbra Collaboration Suite (ZCS) against CVE-2025-66376, a stored cross-site scripting flaw in the Classic UI that attackers could trigger through CSS @import directives in email HTML. The directive set an April 1 remediation deadline under Binding Operational Directive (BOD) 22-01 and urged other organizations to apply vendor mitigations or discontinue use of the product if mitigations were unavailable.
Show sources
- CISA orders feds to patch Zimbra XSS flaw exploited in attacks — www.bleepingcomputer.com — 18.03.2026 21:57
- Russian hackers exploit Zimbra flaw in Ukrainian govt attacks — www.bleepingcomputer.com — 19.03.2026 16:55