A zero-day vulnerability in Zimbra Collaboration Suite (ZCS) was actively used in targeted attacks in early 2025.

The vulnerability, identified as CVE-2025-27915, is a stored cross-site scripting (XSS)that attackers exploited by sending maliciously crafted iCalendar (.ICS) filesto steal sensitive data from victims' email accounts.
The attacks were initially detected by StrikeReady, which began monitoring for unusually large iCalendar files containing JavaScript.
See also: Critical vulnerabilities in the TOTOLINK X6000R Router
One notable attack targeted the Brazilian military, where an attacker, using an IP address of 193.29.58.37, impersonated the Libyan Navy Protocol Office to deliver the then-unknown exploit.
The root of the issue lies in Zimbra's Classic Web Client, which failed to properly sanitize HTML content within iCalendar files. This allowed malicious users to embed malicious JavaScript within an .ICS attachment.
When a user opened an email containing the malicious calendar entry, the script was executed within the user's active session.

This XSS vulnerability, often considered less severe than remote code execution (RCE) vulnerabilities, proved to be extremely effective. It allowed attackers to execute arbitrary code to perform unauthorized actions, including data extraction and session hijacking, without the user's knowledge.
See also: GhostSocks MaaS: Converting compromised devices into proxies
Zimbra addressed the vulnerability on January 27, 2025, releasing updates (versions 9.0.0 P44, 10.0.13, and 10.1.5), although there is evidence that the exploit was used before the fix was available.
Zimbra Vulnerability: Data-Stealing Payload
The JavaScript payload delivered via the exploit is a sophisticated “data stealer” designed specifically for Zimbra webmail. Its capabilities include:
- Credential theft: Creates hidden form fields to capture usernames and passwords from login pages.
- Data Extraction: The script is programmed to steal a wide range of information, including emails, contacts, distribution lists, shared folders, scratch codes, and trusted device information. The stolen data is sent to a server controlled by the attacker.
- Activity Tracking: Monitors user activity and, if the user is inactive, triggers data theft before logging them out.
- Email forwarding: The malware adds a malicious email filter rule to automatically forward the victim's emails to an external address.
- Evasion techniques: To avoid detection, the script uses a 60-second delay before execution, limits its execution to once every three days, and hides user interface elements to conceal its activity.

While direct attribution remains unconfirmed, researchers note that the tactics are similar to those used by a prolific threat actor linked to Russia and the UNC1151 group (which has been linked to the Belarusian government).
See also: CISA added Meteobridge vulnerability to KEV List
This incident highlights the significant threat posed by XSS vulnerabilities in corporate environments and the importance of promptly applying security updates.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
