CVE-2025-66376 is a stored cross-site scripting vulnerability in the Classic UI of Zimbra Collaboration Suite, creating a path to mailbox theft and abuse of the user’s authenticated webmail session.
The flaw was exploited as a zero-day before Zimbra released fixes in November 2025. A joint government advisory associa...