>> All posts

CVE-2025-48700: Zimbra Collaboration Classic UI XSS, exploited in the wild

The short version: CVE-2025-48700 is a cross-site scripting (XSS) flaw in Zimbra Collaboration's Classic Web Client. A crafted email, when viewed in the Classic UI, executes attacker JavaScript in the victim's authenticated session — enough to hijack the session or scrape the mailbox. It's in CISA's KEV catalog with a very short remediation deadline, and thousands of servers were still exposed when CISA raised the alarm. Steady hands: patch, and consider who still uses the Classic UI.

At a glance

FactDetail
Our severity takeHigh — in practice (see below)
CVSS v3.1 (NVD)6.1 — Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS1.8% · 75.5th percentile (2026-07-17)
In CISA KEV?Yes — remediation was due 2026-04-23
Known exploited?Yes — active in-the-wild exploitation reported
Vulnerability typeCWE-79 stored/reflected cross-site scripting → script execution in the victim's webmail session
Requires authenticated session?No attacker auth — the victim just has to view the crafted message in the Classic UI
AffectedZimbra Collaboration Suite 8.8.15, 9.0, 10.0, 10.1 (Classic Web Client)
Fixed in8.8.15 Patch 47 · 9.0.0 Patch 43 · 10.0.12 · 10.1.4 (and later)

What you need to know

Zimbra Collaboration is an internet-facing webmail platform. CVE-2025-48700 is an XSS in the Classic Web Client caused by insufficient sanitization of HTML content — crafted tag structures and attribute values (including an @import directive and other injection vectors) slip script past the filter.

What makes this one nasty is how little the victim has to do:

  • How they use it — an attacker sends a crafted email (or calendar invite / shared document). No malicious attachment to open, no link to click.
  • How it triggers — the script runs when the victim simply views the message in the Classic UI. That's it.
  • What it leads to — script in an authenticated webmail session can steal the session identifier, read mailbox data, or alter account settings — silent account compromise.

Only the Classic Web Client is affected, which bounds the blast radius, but plenty of organizations still run it. When CISA flagged active exploitation, researchers reported over ten thousand exposed, unpatched Zimbra servers online.

How serious we see it

High — above the 6.1 Medium base score.

The CVSS band reflects that it's "only" script execution requiring user interaction. But the practical picture is worse: the interaction is merely reading an email, the payload hijacks live sessions on internet-facing webmail, and it's confirmed exploited in the wild — enough for CISA to set a three-day remediation window. We rate it by what it does to an exposed mail server.

The reassuring part: it's fixed in published patches, it only affects the Classic Web Client, and you can quickly tell whether you're exposed and on an affected build.

Recommendations

Straight from Zimbra's guidance and CISA:

  1. Patch now. Upgrade to 8.8.15 P47 / 9.0.0 P43 / 10.0.12 / 10.1.4 or later.
  2. If you can't patch immediately, reduce Classic UI exposure. The flaw only impacts Classic Web Client users; a Content Security Policy can serve as an interim mitigation against inline script.
  3. Hunt for prior use. Review webmail sessions and account-setting changes for anomalies; look for unexpected mail rules.
  4. If you find evidence of compromise, respond. Invalidate sessions and reset affected users' credentials.
  5. Confirm your exposure first. Verify whether you run an internet-facing, affected Zimbra build with the Classic Web Client in use.

How BreachRisk sees it

BreachRisk works from the outside in. From little more than your domain it discovers internet-facing Zimbra webmail interfaces, fingerprints the version, and flags exposure tied to this KEV-listed flaw — pushed to the top of your results because it's in KEV and actively exploited, not buried in a backlog.

Note the honest limit: this one is triggered by a user viewing a malicious email, so BreachRisk detects and flags the exposed, affected server rather than attempting exploitation. That outside-in view still answers the first question fast — do we run an exposed Zimbra that needs this patch? — so you can go straight to remediation.

References

See your cyber risk, proven.