Over 10,000 Zimbra Collaboration Suite (ZCS) instances exposed online are vulnerable to ongoing attacks exploiting a cross-site scripting (XSS) security flaw, according to nonprofit security organization Shadowserver. Zimbra is a popular email and collaboration software suite used by hundreds of millions of people worldwide, including hundreds of government agencies and thousands of businesses. The vulnerability (tracked as CVE-2025-48700) affects ZCS 8.8.15, 9.0, 10.0, and 10.1 and can allow unauthenticated attackers to access sensitive information after executing arbitrary JavaScript within the user's session. Synacor released security patches to address the flaw in June 2025, when it warned that CVE-2025-48700 exploits require no user interaction and can be triggered when a user views a maliciously crafted email message in the Zimbra Classic UI. On Monday, CISA flagged CVE-2025-48700 as being abused in the wild and added it to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. The U.S. cybersecurity agency also ordered Federal Civilian Executive Branch (FCEB) agencies to secure their Zimbra servers within three days, by April 23. On Friday, Internet security watchdog Shadowserver also warned that over 10,500 Zimbra servers exposed online remain unpatched, most of them in Asia (3,794) and Europe (3,793). While CISA didn't share any details about CVE-2025-48700 attacks, another XSS vulnerability (tracked as CVE-2025-66376 and patc...
Over 10,000 Zimbra servers vulnerable to ongoing XSS attacks
BleepingComputer
·Sergiu Gatlan
·Published Apr 24, 2026
·Updated
Affected Software
4 affected components
Synacor Zimbra Collaboration Suite=8.8.15
Synacor Zimbra Collaboration Suite=9.0
Synacor Zimbra Collaboration Suite=10.0
Synacor Zimbra Collaboration Suite=10.1
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the vulnerability of over 10,000 Zimbra servers to cross-site scripting (XSS) attacks.
2
What security implications are discussed regarding Zimbra servers?
The article highlights that a security flaw is being actively exploited in Zimbra servers, putting sensitive data at risk.
3
What software is affected by the vulnerabilities mentioned in the article?
The affected software is the Zimbra Collaboration Suite (ZCS), specifically by Synacor.
4
How many Zimbra servers are reported to be vulnerable in the article?
The article states that over 10,000 Zimbra servers are currently vulnerable to exploitation.
5
Who reported the ongoing exploitation of the Zimbra flaw?
The nonprofit security organization Shadowserver reported the exploitation of the Zimbra flaw.