<html><body><div style="font-family: arial, helvetica, sans-serif; font-size: 12pt; color: #000000"><div>Hi Everyone,</div><div><br data-mce-bogus="1"></div><div>For the benefit of awareness of those subscribed to the Zeta Alliance mailing list, here is a advisory released today by CISA in the US related to active exploitation of vulnerabilities in Zimbra: <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a">https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a</a><br data-mce-bogus="1"></div><div><br data-mce-bogus="1"></div><div>This advisory includes indicators of compromise you can use for checking your own Zimbra servers, and shares this advice:</div><div><br data-mce-bogus="1"></div><div>According to the National Vulnerability Database (NVD), CVE-2025-66376 was initially published on 5 January 2026. This vulnerability allows for execution of a JavaScript payload included in email content due to improper sanitization of Cascading Style Sheet\u2019s (CSS) @import directives within an email [5]. Because the activity attributed to this campaign began in July 2025\u2014months before Synacor released a patch and the CVE was published\u2014the payload initially exploited a zero-day vulnerability at that time [T1587.004]. </div><div><br data-mce-bogus="1"></div><div data-marker="__SIG_PRE__"><div><div><div><span style="color:rgb( 255 , 102 , 0 );font-weight:bold"><br>Randy Leiker (</span><span style="font-weight:bold"> <span style="color:rgb( 51 , 51 , 255 );background-color:rgb( 255 , 255 , 255 )">randy@skywaynetworks.com</span> <span style="color:rgb( 255 , 102 , 0 )">)</span></span><br><span style="color:rgb( 0 , 0 , 153 )">Skyway Networks, LLC</span></div></div></div></div></div></body></html>