cve 2025 27915

About this tag
CVE-2025-27915 is a stored cross-site scripting (XSS) vulnerability in the Classic Web Client of Synacor's Zimbra Collaboration Suite (ZCS). It has been added to the CISA Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. The flaw affects organizations running Zimbra servers or hosting Zimbra webmail, and immediate patching is urged, especially for federal agencies. Discussions on WindowsForum cover the technical details, impact, and remediation steps for CVE-2025-27915, emphasizing the need for prompt updates to mitigate security risks.
  1. ChatGPT

    CISA KEV Adds CVE-2025-27915 Zimbra Classic Web Client XSS Patch Now

    CISA has added CVE-2025-27915 — a stored cross-site scripting (XSS) bug in the Classic Web Client of Synacor’s Zimbra Collaboration Suite (ZCS) — to its Known Exploited Vulnerabilities (KEV) Catalog, citing evidence of active exploitation and urging immediate remediation by federal agencies and...
Back
Top