Zimbra Collaboration Suite actively exploited XSS flaw (CVE-2025-48700)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2025-48700 is an actively exploited XSS flaw in Zimbra Collaboration Suite (ZCS) that can let unauthenticated attackers run JavaScript inside a user's session and access sensitive information. The issue affects ZCS 8.8.15, 9.0, 10.0, and 10.1, making the vulnerable surface broad across deployed Zimbra versions. More than 10,000 exposed instances are reported vulnerable online, which increases the chance of mass abuse. CISA has placed the flaw in the KEV Catalog, confirming real-world exploitation and urgent remediation needs.
Related Happenings
Zimbra Classic Web Client stored XSS cross-site scripting flaw
Vulnerability
H score22
First: 10.07.2026 14:47
Last: 10.07.2026 14:47
Sources 1
About this happening:
Zimbra's Classic Web Client stored cross-site scripting (XSS) flaw was patched in Zimbra 10.1.19, closing a path that could expose session data, account settings...
Zimbra Classic Web Client stored XSS cross-site scripting flaw
VulnerabilityAbout this happening: Zimbra's Classic Web Client stored cross-site scripting (XSS) flaw was patched in Zimbra 10.1.19, closing a path that could expose session data, account settings...
APT28 Operation GhostMail Zimbra phishing campaign targeting Ukrainian government entities
Campaign
H score37
First: 19.03.2026 16:55
Last: 19.03.2026 16:55
Sources 1
About this happening:
APT28’s Operation GhostMail is actively targeting Ukrainian government entities through a phishing chain that exploits CVE-2025-66376 in Zimbra Collaboration Sui...
APT28 Operation GhostMail Zimbra phishing campaign targeting Ukrainian government entities
CampaignAbout this happening: APT28’s Operation GhostMail is actively targeting Ukrainian government entities through a phishing chain that exploits CVE-2025-66376 in Zimbra Collaboration Sui...
CISA patch guidance for Zimbra and SharePoint flaws
Advisory/Mitigation
H score56
First: 19.03.2026 08:05
Last: 19.03.2026 08:05
Sources 1
About this happening:
CISA told FCEB agencies to patch two actively exploited vulnerabilities in Synacor Zimbra Collaboration Suite (ZCS) and Microsoft Office SharePoint, creating i...
CISA patch guidance for Zimbra and SharePoint flaws
Advisory/MitigationAbout this happening: CISA told FCEB agencies to patch two actively exploited vulnerabilities in Synacor Zimbra Collaboration Suite (ZCS) and Microsoft Office SharePoint, creating i...
Zimbra Collaboration Suite (ZCS) stored XSS flaw (CVE-2025-66376)
Vulnerability
H score52
First: 18.03.2026 21:57
Last: 18.03.2026 21:57
Sources 1
About this happening:
CVE-2025-66376 affects Zimbra Collaboration Suite (ZCS), where a stored XSS flaw in the Classic UI is actively exploited and can put exposed mail servers and u...
Zimbra Collaboration Suite (ZCS) stored XSS flaw (CVE-2025-66376)
VulnerabilityAbout this happening: CVE-2025-66376 affects Zimbra Collaboration Suite (ZCS), where a stored XSS flaw in the Classic UI is actively exploited and can put exposed mail servers and u...
Sangoma FreePBX web shell exploitation wave (CVE-2025-64328)
Exploitation Wave
H score41
First: 27.02.2026 19:59
Last: 27.02.2026 19:59
Sources 1
About this happening:
More than 900 Sangoma FreePBX instances remain web-shell infected after an ongoing exploitation wave tied to CVE-2025-64328. The affected systems span the U.S....
Sangoma FreePBX web shell exploitation wave (CVE-2025-64328)
Exploitation WaveAbout this happening: More than 900 Sangoma FreePBX instances remain web-shell infected after an ongoing exploitation wave tied to CVE-2025-64328. The affected systems span the U.S....
Timeline
-
24.04.2026 16:35 2 articles · 2mo ago
Zimbra Collaboration Suite actively exploited XSS flaw (CVE-2025-48700)
Initial DisclosureThe CVE-2025-48700 XSS issue surfaced as a patched weakness in Zimbra Collaboration Suite that could run attacker JavaScript inside a user's session. It then became a live exploitation concern as exposed servers remained online and defenders confirmed abuse in the wild.
Show sources
- Over 10,000 Zimbra servers vulnerable to ongoing XSS attacks — www.bleepingcomputer.com — 24.04.2026 16:35
- Over 10,000 Zimbra servers vulnerable to ongoing XSS attacks — www.bleepingcomputer.com — 24.04.2026 16:35