News Summary:
On August 26, 2026, researchers warned that hackers breached hundreds of internet-facing Zimbra Collaboration Suite (ZCS) instances through a vulnerability that had been patched the previous month. ZCS provides email, calendars, contacts, and administrative services to millions of users globally. This follows a confirmation on April 24, 2026, by security researchers that over 10,000 Zimbra instances remained exposed online and vulnerable to active exploitation of a critical cross-site scripting (XSS) flaw, tracked as CVE-2025-48700. Earlier, on March 19, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a critical vulnerability affecting ZCS to its Known Exploited Vulnerabilities (KEV) catalog, signaling confirmed in-the-wild abuse and setting an April 1, 2026 remediation deadline for federal agencies. This CISA action followed its March 17, 2026 mandate for an emergency patch for a high-severity XSS vulnerability (CVE-2025-66376) in Zimbra, which it also added to the KEV catalog. Previously, on January 2, 2026, the Federal Office for Information Security (BSI) issued an update to a security warning, originally published on December 22, 2025, regarding multiple high-risk vulnerabilities in Synacor Zimbra that affected Linux and UNIX operating systems.
Subscribe for full access to Synacor's profile