• News/
  • https://www.bleepingcomputer.com/news/security/cisa-says-zimbra-flaw-now-exploited-over-10k-servers-vulnerable/

Over 10,000 Zimbra servers vulnerable to ongoing XSS attacks

BleepingComputer
·
Sergiu Gatlan
·
Published Apr 24, 2026
·
Updated

Over 10,000 Zimbra Collaboration Suite (ZCS) instances exposed online are vulnerable to ongoing attacks exploiting a cross-site scripting (XSS) security flaw, according to nonprofit security organization Shadowserver. Zimbra is a popular email and collaboration software suite used by hundreds of millions of people worldwide, including hundreds of government agencies and thousands of businesses. The vulnerability (tracked as CVE-2025-48700) affects ZCS 8.8.15, 9.0, 10.0, and 10.1 and can allow unauthenticated attackers to access sensitive information after executing arbitrary JavaScript within the user's session​​. Synacor released security patches to address the flaw in June 2025, when it warned that CVE-2025-48700 exploits require no user interaction and can be triggered when a user views a maliciously crafted email message in the Zimbra Classic UI. On Monday, CISA flagged CVE-2025-48700 as being abused in the wild and added it to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. The U.S. cybersecurity agency also ordered Federal Civilian Executive Branch (FCEB) agencies to secure their Zimbra servers within three days, by April 23. On Friday, Internet security watchdog Shadowserver also warned that over 10,500 Zimbra servers exposed online remain unpatched, most of them in Asia (3,794) and Europe (3,793). While CISA didn't share any details about CVE-2025-48700 attacks, another XSS vulnerability (tracked as CVE-2025-66376 and patc...

Read full article

Affected Software

4 affected components
Synacor Zimbra Collaboration Suite=8.8.15
Synacor Zimbra Collaboration Suite=9.0
Synacor Zimbra Collaboration Suite=10.0
Synacor Zimbra Collaboration Suite=10.1
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the vulnerability of over 10,000 Zimbra servers to cross-site scripting (XSS) attacks.

2

What security implications are discussed regarding Zimbra servers?

The article highlights that a security flaw is being actively exploited in Zimbra servers, putting sensitive data at risk.

3

What software is affected by the vulnerabilities mentioned in the article?

The affected software is the Zimbra Collaboration Suite (ZCS), specifically by Synacor.

4

How many Zimbra servers are reported to be vulnerable in the article?

The article states that over 10,000 Zimbra servers are currently vulnerable to exploitation.

5

Who reported the ongoing exploitation of the Zimbra flaw?

The nonprofit security organization Shadowserver reported the exploitation of the Zimbra flaw.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203