Find notable cyber news and cases, enriched with sources, timelines, and signals.

CISA BOD 22-01 Zimbra patch order

Public Sector Action
First reported
Last updated
Happening score
H score 34
1 unique sources, 2 articles

Summary

Hide ▲

CISA ordered Federal Civilian Executive Branch agencies to secure Zimbra Collaboration Suite (ZCS) servers against CVE-2025-66376, an actively exploited flaw that could enable session hijacking and data theft. The directive gave agencies two weeks to act, with a deadline of April 1st, because exposed mail systems remain a live attack surface. CISA also urged other organizations to patch or mitigate the issue as soon as possible.

Related Happenings

CISA KEV directive for Joomla extension flaws

Public Sector Action
H score36 First: 13.07.2026 18:20 Last: 13.07.2026 18:20 Sources 1

About this happening: CISA added the Joomla extension flaws to the KEV catalog and ordered federal agencies to apply updates or mitigations within three days, tightening remediation tim...

Zimbra Classic Web Client stored XSS cross-site scripting flaw

Vulnerability
H score26 First: 11.07.2026 09:45 Last: 11.07.2026 09:45 Sources 1

About this happening: Zimbra fixed a critical stored XSS flaw in the Classic Web Client that could let a specially crafted email run malicious code in a user's session. The weakness cou...

Zimbra Classic Web Client stored XSS security update

Security Patch Release
H score32 First: 10.07.2026 14:47 Last: 10.07.2026 14:47 Sources 1

About this happening: Zimbra released ZCS v10.1.19 to patch a stored XSS flaw in the Classic Web Client, narrowing exposure for users of that interface. The bug could be triggered through *...

Zimbra Classic Web Client stored XSS cross-site scripting flaw

Vulnerability
H score22 First: 10.07.2026 14:47 Last: 10.07.2026 14:47 Sources 1

About this happening: Zimbra's Classic Web Client stored cross-site scripting (XSS) flaw was patched in Zimbra 10.1.19, closing a path that could expose session data, account settings...

CISA KEV remediation order for CVE-2026-48907

Public Sector Action
H score89 First: 17.06.2026 08:50 Last: 17.06.2026 08:50 Sources 1

About this happening: CISA added CVE-2026-48907 to the KEV catalog and ordered FCEB agencies to apply fixes by June 19, 2026, forcing federal remediation of an actively exploited Jo...

Timeline

  1. 18.03.2026 21:57 2 articles · 3mo ago

    CISA orders federal agencies to patch Zimbra CVE-2025-66376

    Legal Policy Action Update

    CISA ordered U.S. federal civilian agencies to secure Zimbra Collaboration Suite (ZCS) against CVE-2025-66376, a stored cross-site scripting flaw in the Classic UI that attackers could trigger through CSS @import directives in email HTML. The directive set an April 1 remediation deadline under Binding Operational Directive (BOD) 22-01 and urged other organizations to apply vendor mitigations or discontinue use of the product if mitigations were unavailable.

    Show sources