Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.
https://www.securityweek.com/russian-apt-exploits-zimbra-vulnerability-against-ukraine/
https://therecord.media/russia-hackers-ukraine-zimbra-breach
https://thehackernews.com/2026/03/cisa-warns-of-zimbra-sharepoint-flaw.html
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-66376
https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy
https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.13#Security_Fixes
https://wiki.zimbra.com/wiki/Zimbra_Releases/10.0.18#Security_Fixes