Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

CISA Warns of Zimbra Collaboration Suite (ZCS) XSS Zero-Day Vulnerability Actively Exploited in Attacks

Posted on October 8, 2025October 8, 2025 By CWS

CISA has issued a vital warning concerning a zero-day cross-site scripting (XSS) vulnerability in Synacor’s Zimbra Collaboration Suite (ZCS), designated as CVE-2025-27915. 

This vulnerability has been actively exploited in assaults and poses important dangers to organizations utilizing the favored electronic mail and collaboration platform.

Zimbra Collaboration Suite (ZCS) XSS Flaw

The vulnerability exists throughout the Traditional Net Shopper part of Zimbra Collaboration Suite and stems from inadequate sanitization of HTML content material in ICS (Web Calendar System) recordsdata. 

The safety flaw is classed below CWE-79, which particularly addresses improper neutralization of enter throughout internet web page era.

When customers view electronic mail messages containing malicious ICS entries, embedded JavaScript code executes mechanically by means of an ontoggle occasion handler inside a tag. 

This exploitation vector permits attackers to run arbitrary JavaScript code throughout the sufferer’s authenticated session context. 

The assault mechanism bypasses normal safety controls by leveraging reliable calendar file performance to ship malicious payloads.

The vulnerability’s exploitation requires minimal consumer interplay – merely viewing a specifically crafted electronic mail message triggers the malicious code execution. 

This low barrier to exploitation makes it notably harmful for widespread assaults focusing on a number of organizations concurrently.

Threat FactorsDetailsAffected ProductsZimbra Collaboration Suite (ZCS) 10.1.9ZCS 10.0.15ZCS 9.0.0 Patch 46ImpactCross-site scriptingExploit PrerequisitesVictim should view a crafted electronic mail containing a malicious ICS calendar entry within the Traditional Net Shopper; consumer interplay required; attacker wants a legitimate account or electronic mail supply capabilityCVSS 3.1 Score5.4 (Medium)

Mitigations

The profitable exploitation of CVE-2025-27915 permits attackers to carry out unauthorized actions inside compromised consumer accounts, together with the creation of malicious electronic mail filters that redirect incoming messages to attacker-controlled addresses. 

This functionality facilitates complete knowledge exfiltration and ongoing surveillance of sufferer communications.

CISA has designated October 28, 2025, because the necessary remediation deadline for federal companies below Binding Operational Directive (BOD) 22-01. 

Organizations should apply vendor-provided mitigations, implement relevant cloud service steerage, or discontinue product utilization if efficient mitigations stay unavailable.

The company emphasizes that this vulnerability’s lively exploitation standing requires speedy consideration from all Zimbra Collaboration Suite directors. 

Safety groups ought to monitor the official Zimbra Safety Heart and Nationwide Vulnerability Database for up to date mitigation steerage and patches. 

Organizations must also implement further electronic mail safety controls, together with enhanced attachment scanning and consumer consciousness coaching targeted on suspicious calendar invites and ICS file attachments.

Cyber Consciousness Month Supply: Upskill With 100+ Premium Cybersecurity Programs From EHA’s Diamond Membership: Be part of At present

Cyber Security News Tags:Actively, Attacks, CISA, Collaboration, Exploited, Suite, Vulnerability, Warns, XSS, ZCS, ZeroDay, Zimbra

Post navigation

Previous Post: Exploitation of Oracle EBS Zero-Day Started 2 Months Before Patching
Next Post: Hackers Weaponizing WordPress Websites by Injecting Malicious PHP Codes Silently

Related Posts

Fire Ant Hackers Exploiting Vulnerabilities in VMware ESXi and vCenter Cyber Security News
20 Best Inventory Management Tools in 2025 Cyber Security News
“AI-Induced Destruction” – Helpful Tools Become Accidental Weapons Cyber Security News
Hackers Actively Scanning to Exploit Palo Alto Networks PAN-OS Global Protect Vulnerability Cyber Security News
macOS Gatekeeper Explained: Strengthening System Defenses Cyber Security News
Threat Actor Allegedly Selling FortiGate API Exploit Tool Targeting FortiOS Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Radiflow Unveils New OT Security Platform
  • Ransomware Group Claims Attack on Beer Giant Asahi
  • Hackers Weaponizing WordPress Websites by Injecting Malicious PHP Codes Silently
  • CISA Warns of Zimbra Collaboration Suite (ZCS) XSS Zero-Day Vulnerability Actively Exploited in Attacks
  • Exploitation of Oracle EBS Zero-Day Started 2 Months Before Patching

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Radiflow Unveils New OT Security Platform
  • Ransomware Group Claims Attack on Beer Giant Asahi
  • Hackers Weaponizing WordPress Websites by Injecting Malicious PHP Codes Silently
  • CISA Warns of Zimbra Collaboration Suite (ZCS) XSS Zero-Day Vulnerability Actively Exploited in Attacks
  • Exploitation of Oracle EBS Zero-Day Started 2 Months Before Patching

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News