A three-day window: cross-site scripting in a mail platform listed 17 times
Added on 20 April 2026 with a remediation date of 23 April. A three-day window occurs in only 101 of the 1,695 KEV records kept here. Zimbra appears in the catalog 17 times.
Key facts
- CVE IDCVE-2025-48700
- Affected (vendor / product)Synacor Zimbra Collaboration Suite (ZCS)
- CWECWE-79
- ExploitationListed in CISA KEV (exploitation confirmed)
- Remediation due2026-04-23 (U.S. federal civilian agencies, BOD 22-01)
Key points
- A cross-site scripting flaw in Zimbra Collaboration Suite allowing arbitrary JavaScript inside a user session.
- Added 20 April 2026 with a 23 April deadline: a three-day window.
- Only 101 of 1,695 records (6.0%) have a window of three days or less; the largest band is 15 to 21 days at 1,025 (60.5%).
- Zimbra appears 17 times, eight of them the same cross-site scripting weakness.
1Three days
The previous article had a window of twenty-one days. This one has three. Of the 1,695 KEV records this site holds as of 2026-09-06, only 101 (6.0%) carry a window of three days or less.
The length of a window is not set by severity alone. What it does change is practice: a short window leaves little room to sequence the response.
2The same type recurring in the same product
Splitting Zimbra's 17 entries by weakness type, nearly half are the same cross-site scripting flaw (CWE-79).
Identifier years run from 2018 to 2026, with five from 2022 the largest single year. In collaboration platforms with a web interface, the same input-handling family recurs.
3What can happen
Cross-site scripting lets an attacker's script run in a legitimate user's browser with the privileges of the site. Here the record describes arbitrary JavaScript executing within a user session, potentially reaching sensitive information. A mail platform is a screen reached after authentication, so a script running there sees what the user sees.
The next article takes up a product listed exactly twice.
Why it matters
A remediation deadline works directly as a priority signal. Records with a window of a few days will not fit ordinary change management, so an emergency path has to exist in advance.
FAQ
What sets the length of the window?
Why does cross-site scripting matter?
Why does one product repeat the same weakness type?
Sources (primary)
This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.
- CISA KEV Catalog (known exploited list)
- NVD (CVE details / CVSS)
- Vendor / reference advisory
- This product uses data from the NVD API but is not endorsed or certified by the NVD. KEV data is CC0 (public domain).