Zimbra calendar-attachment XSS abuse
Case score 64
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 64
- Main story score
- 62
- Related evidence lift
- +2 / 20
- Contributing updates
- 1
- Context updates
- 1
- Vulnerability Base event: CVE-2025-27915 in Zimbra Collaboration Suite with malicious ICS attachment abuse. main
- Campaign Targeted espionage campaign using the same CVE against the Brazilian military; adds support evidence. contributes
- Security Patch Release Vendor fix for CVE-2025-27915; remediation context only. context
Overview
Latest development Open development history Zimbra patches CVE-2025-27915 in Zimbra Collaboration Zimbra Collaboration released 9.0.0 Patch 44, 10.0.13, and 10.1.5 on January 27, 2025 to fix CVE-2025-27915, a stored cross-site scripting vulnerability in the Classic Web Client caused by insufficient sanitization of HTML content in ICS calendar files.
-
StrikeReady identifies Zimbra zero-day exploitation through ICS attachments
StrikeReady identified zero-day exploitation of CVE-2025-27915 in Zimbra Collaboration Suite (ZCS 9.0, 10.0, and 10.1) through .ICS/iCalendar email attachments that delivered Base64-obfuscated JavaScript; the campaign spoofed the Libyan Navy’s Office of Protocol, targeted a Brazilian military organization, and sought to steal Zimbra Webmail credentials, emails, contacts, and shared folders while adding forwarding filters.
-
Brazilian military targeted with malicious ICS file exploiting Zimbra CVE-2025-27915
An unknown threat actor masquerading as the Libyan Navy's Office of Protocol targeted the Brazilian military with a malicious ICS email attachment that exploited CVE-2025-27915 in Zimbra Classic Web client, using the payload for credential theft, email and contact exfiltration, folder access, filter-rule manipulation, and MFA bypass support. StrikeReady Labs said the campaign was unusual because it relied on direct exploitation of an open source collaboration tool via an email attachment, and Zimbra later released ZCS 10.1.9 in June as a fix after the zero-day abuse had already occurred.
-
Unknown actors exploit Zimbra zero-day against the Brazilian military
StrikeReady Labs reported on September 30, 2025 that unknown threat actors spoofing the Libyan Navy's Office of Protocol used malicious ICS files to exploit Zimbra Collaboration CVE-2025-27915 as a zero-day against the Brazilian military. The embedded JavaScript executed through an ontoggle event inside a details tag and was designed to steal credentials, emails, contacts, and shared folders, while also creating a Zimbra filter named Correo that forwarded messages to [email protected].