CVE-2025-27915

Published Mar 12, 2025

Last updated 4 months ago

Overview

Description
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the Classic Web Client due to insufficient sanitization of HTML content in ICS files. When a user views an e-mail message containing a malicious ICS entry, its embedded JavaScript executes via an ontoggle event inside a <details> tag. This allows an attacker to run arbitrary JavaScript within the victim's session, potentially leading to unauthorized actions such as setting e-mail filters to redirect messages to an attacker-controlled address. As a result, an attacker can perform unauthorized actions on the victim's account, including e-mail redirection and data exfiltration.
Source
cve@mitre.org
NVD status
Analyzed
Products
zimbra_collaboration_suite

Risk scores

CVSS 3.1

Type
Secondary
Base score
5.4
Impact score
2.7
Exploitability score
2.3
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Severity
MEDIUM

Known exploits

Data from CISA

Vulnerability name
Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability
Exploit added on
Oct 7, 2025
Exploit action due
Oct 28, 2025
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-79

Social media

Hype score
Not currently trending
  1. A zero-day flaw (CVE-2025-27915) in Zimbra was used to target Brazil’s military via malicious ICS/calendar files. (The Hacker 😮 Why it’s relevant: If your business uses collaboration tools, even something as innocuous as a calendar inv it could be an entry point. 🛡 Yo

    @BGMloop

    7 Nov 2025

    29 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  2. ⚠️ XSS in Zimbra (CVE-2025-27915) lets JS run via an email with a malicious .ics — exploit published Sep 30; used in the wild vs Brazil’s military before Jan 27 patch. #Zimbra #StrikeReadyLabs ➡️ https://t.co/tJTVdqpKe2 https://t.co/s3YiDVeQUv

    @leonov_av

    26 Oct 2025

    81 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 💥 El CVE-2025-27915 ha puesto a Zimbra bajo ataque. Miles de empresas están en riesgo por una vulnerabilidad crítica. 🔐 Aprende cómo proteger tu sistema antes de que sea tarde: actualiza, refuerza y monitoriza. 👉 Mantente informado y lleva tu seguridad al siguiente ni

    @MMarcoSeguridad

    23 Oct 2025

    25 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Actively exploited CVE : CVE-2025-27915

    @transilienceai

    19 Oct 2025

    25 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  5. ⚔️ Hackers atacaron al ejército de #Brasil explotando una falla crítica en #Zimbra (CVE-2025-27915) mediante archivos ICS maliciosos 📷El fallo permitió ejecutar código oculto y robar correos y credenciales. 🔗 https://t.co/DcDURQOby2 https://t.co/skbEbedKhC

    @ojo_cibernetico

    18 Oct 2025

    118 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. ⚔️ Hackers atacaron al ejército de #Brasil explotando una falla crítica en #Zimbra (CVE-2025-27915) mediante archivos ICS maliciosos 📅💻 El fallo permitió ejecutar código oculto y robar correos y credenciales. 🔗 https://t.co/jhoqF7Lq99 https://t.co/hehwOHh71k

    @ojo_cibernetico

    18 Oct 2025

    33 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 🚨 El ataque a Zimbra (CVE-2025-27915) nos deja una lección clara: nadie está a salvo si no actualiza a tiempo. 🔧 Los fallos en correo empresarial son una de las puertas más usadas por los atacantes. 👉 Mantén tus sistemas al día y protege tus datos. 💬 ¿Tu empres

    @MMarcoSeguridad

    16 Oct 2025

    41 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. ⚠️ Attackers Exploit Zimbra Zero-Day via ICS Calendar File https://t.co/d2s9wRlT7m A state-linked actor masquerading as the Libyan Navy delivered a malicious ICS file exploiting an XSS flaw (CVE-2025-27915) in Zimbra’s web client to steal credentials, emails, manipulate

    @Huntio

    13 Oct 2025

    3059 Impressions

    11 Retweets

    27 Likes

    8 Bookmarks

    0 Replies

    0 Quotes

  9. زيمبرا — استـ ـغلال CVE-2025-27915 يستـ ـهدف الجيش البرازيلي التفاصيل .. https://t.co/1np05Ei4nE #مركز_الأمن_السيبراني_للابحاث_والدراسات https://t.co/8lriD7uV1r

    @ccforrs

    12 Oct 2025

    52 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. 🛡️ Cyber Threat Digest – 2025-10-09 KEV: CVE-2025-27915 — Synacor Zimbra Collaboration Suite NVD: CVE-2025-11476 — vulnerability was identified in News: Azure outage blocks access to Microsoft… #cybersecurity #infosec #CVE More: https://t.co/J1fpKfnDnv

    @dpharristech

    9 Oct 2025

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. Una vulnerabilidad Zero-Day pone en riesgo a Zimbra: CVE-2025-27915 https://t.co/LUZYJrfInr #Internet #Noticia #Tecnología #CiberSeguridad #web #Vulnerabilidad vía @unaaldia https://t.co/nwwnijYIhJ

    @Securizame

    9 Oct 2025

    266 Impressions

    0 Retweets

    4 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. New Post: Vulnerabilidad Zero-Day pone en riesgo a Zimbra | CVE-2025-27915 https://t.co/DuPMELFNbs

    @hualkana

    8 Oct 2025

    36 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. ⚠️ Zimbra bajo ataque #ZeroDay (CVE-2025-27915) — se están robando correos y datos en empresas de todo el mundo. Si usas Zimbra, parchea YA y revisa 💼 En @MMarcoSeguridad y @Ciberseguridad24h ayudamos a prevenir ataques y cumplir el #RGPD. 🌐 https://t.co/liiwnqVm89 h

    @MMarcoSeguridad

    8 Oct 2025

    33 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. 🛡️ Cyber Threat Digest – 2025-10-08 KEV: CVE-2025-27915 — Synacor Zimbra Collaboration Suite NVD: CVE-2021-22291 — Improper Neutralization of Input News: Salesforce refuses to pay ransom over… #cybersecurity #infosec #CVE More: https://t.co/J1fpKfnDnv

    @dpharristech

    8 Oct 2025

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. csirt_it: ‼ #Zimbra: rilevato lo sfruttamento attivo in rete della vulnerabilità CVE-2025-27915 - già sanata dal vendor – relativa a #ZCS (Zimbra Collaboration Suite) Rischio: 🟠 🔗 https://t.co/u4OCBze842 ⚠ Importante aggiornare i prodotti interess… https://t.co

    @Vulcanux_

    8 Oct 2025

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. Latest Known Exploited Vulnerabilities (#KEV) : #CVE-2025-27915 #Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability https://t.co/S6C2XShLlb

    @ScyScan

    7 Oct 2025

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. هجوم إلكتروني يستهدف مستخدمي Zimbra عبر ملفات التقويم! يستغل المهاجمون ثغرة يوم الصفر (CVE-2025-27915) في نظام Zimbra من خلال ملفات iCalendar (.ICS) تحتوي على تعليمات JavaScript خ

    @ChbibAnas

    7 Oct 2025

    13 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  18. 🛡️ We added Synacor Zimbra Collaboration Suite vulnerability CVE-2025-27915 to our Known Exploited Vulnerabilities Catalog. Visit https://t.co/myxOwap1Tf &amp; apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https://t.co/f3UouEQBA3

    @CISACyber

    7 Oct 2025

    3677 Impressions

    9 Retweets

    18 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  19. ⚠️Vulnerabilidad en Zimbra ❗CVE-2025-27915 ➡️Más info: https://t.co/2Jq833GNf8 https://t.co/NGdajzhVql

    @CERTpy

    7 Oct 2025

    106 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  20. 🔓 تم استغلال ثغرة Zero-Day في Zimbra (CVE-2025-27915) لاستهداف البرازيل عبر ملفات ICS خبيثة، تُنفّذ تعليمات جافاسكريبت ضمن جلسات البريد الإلكتروني. #Zimbra #ThreatIntel #أمن_معل

    @f16roo

    6 Oct 2025

    6 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  21. 💥 hackers broke Zimbra Collaboration SuiteUsing Zero-Day Vulnerability Cve-2025-27915 through files Icalendar (.ICS). This allowed them introduce harmful javascript, steal letters, logins, contacts and transfer data to third -party addresses. Company Strikeready discovered an

    @Hack_Your_Mom

    6 Oct 2025

    13 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. 🚨 CORTEX Protocol Alert: Zimbra zero-day (CVE-2025-27915) exploited via weaponized iCalendar files. Attackers hijack sessions + steal emails. Patch immediately. CORTEX: revoke sessions, block .ICS, audit rules. https://t.co/gSEqw07Yth

    @the_c_protocol

    6 Oct 2025

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. #exploit #AppSec #Threat_Research 1⃣ Zimbra Exploit Analysis (CVE-2025-27915) https://t.co/8ovnzHtvXB // These exploits take advantage of .ics files to breach vulnerable systems 2⃣ Notepad++ DLL Hijacking (CVE-2025-56383) https://t.co/RGih3h81ws // If the threat actor has t

    @ksg93rd

    6 Oct 2025

    45 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  24. A security vulnerability, identified as CVE-2025-27915, was discovered in the Zimbra Collaboration Suite (ZCS) and exploited in zero-day attacks in January 2025. This flaw stemmed from insufficient sanitization of HTML content in iCalendar (.ICS) files. The zero-day https://t.co/

    @CTIAcademy

    6 Oct 2025

    207 Impressions

    2 Retweets

    4 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  25. Zimbra zero-day (CVE-2025-27915) exploited Brazilian military via malicious ICS files (XSS). Patch released! 🛡️ https://t.co/Re1lUypbC7 #Zimbra #ZeroDay #CyberSecurity #BrazilianMilitary #XSS

    @0xT3chn0m4nc3r

    6 Oct 2025

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. 📌 تم استغلال ثغرة أمنية في Zimbra Collaboration لشن هجمات إلكترونية على الجيش البرازيلي باستخدام ملفات ICS خبيثة. تم تصنيف الثغرة، CVE-2025-27915، على أنها XSS مخزنة نتيجة

    @Cybercachear

    6 Oct 2025

    55 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  27. A “harmless” ICS calendar file exploited Zimbra’s XSS zero-day flaw (CVE-2025-27915) — turning an invite into a full data stealer. Target: Brazil’s military. The script waited 72 hours before exfiltrating credentials. Read → https://t.co/cMtaf1a8lN

    @TheHackersNews

    6 Oct 2025

    16316 Impressions

    45 Retweets

    110 Likes

    32 Bookmarks

    5 Replies

    2 Quotes

  28. Zimbraの脆弱性CVE-2025-27915がゼロデイ攻撃に悪用される https://t.co/rWHBqFKQsv #Security #セキュリティー #ニュース

    @SecureShield_

    6 Oct 2025

    89 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  29. Zero-day flaw CVE-2025-27915 in Zimbra Collaboration Suite exploited via malicious iCalendar files enables JavaScript payload delivery, targeting military orgs. Attribution hints at Russian and Belarusian groups. #ZimbraFlaw #ICSattack #Belarus https://t.co/K9a9G9cDeo

    @TweetThreatNews

    5 Oct 2025

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  30. Zimbra Collaboration Suite has patched critical vulnerabilities, including XSS, SQLi, and SSRF. Important to apply updates to maintain security. CVE-2025-27915, CVE-2025-25064, CVE-2025-25065. 🔒 #Zimbra #DataProtection #USA link: https://t.co/fFVt5BVFdz https://t.co/zjX96qTX5y

    @TweetThreatNews

    20 Mar 2025

    24 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations