Skip to content
The Cybersecurity Focus
The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

  • Home
  • Home
The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

  • Home
  • Home
CVEIncidentPhishing

Zimbra CVE: Russian Spies Exploit Zero-Click XSS

By ogwatermelon
July 25, 2026 4 Min Read
0
July 23, 2026

A Russian state-sponsored advanced persistent threat group known as Laundry Bear (also called Void Blizzard) has been silently reading Western mailboxes by exploiting a stored cross-site scripting vulnerability in Zimbra Collaboration Suite. The campaign was first observed in July 2025 and continues to target government, defense, and commercial organizations. A joint advisory published by CISA, the NSA, and international partners on July 23, 2026, warns that the flaw requires only viewing a malicious email to trigger exploitation.

What Happened: Russian Spies Steal Mail and 2FA Codes via Zimbra Zero-Click Exploit

LAUNDRY BEAR is a Russian state-supported APT cluster first publicly identified by Dutch intelligence agencies in May 2025. Microsoft tracks the same actors under the name Void Blizzard. Furthermore, the group has been linked to compromises of NATO-aligned organizations, Ukrainian entities, and critical infrastructure operators across government, defense, energy, and technology sectors.

The latest campaign leverages a stored XSS vulnerability in Zimbra Collaboration Suite tracked as CVE-2025-66376. The flaw resides in the Classic Web Client’s CSS handling, where a crafted HTML email uses a technique called “tag-splitting” to bypass Zimbra’s sanitizer. Consequently, JavaScript executes automatically when a user simply opens or previews the message. No clicks, no downloads, and no additional user interaction are required.

The advisory highlights that LAUNDRY BEAR exploited this vulnerability as a zero-day for at least five months before Zimbra patched it in November 2025. Despite the patch being available, threat actors continue to successfully target unpatched instances, indicating a large vulnerable footprint remains.

Technical Details of the Zimbra Exploit

The attack begins with a crafted HTML email sent from adversary-controlled or compromised accounts. The email body contains a hidden payload using a technique Proofpoint calls “tag-splitting.” An svg onload tag is broken apart and hidden inside fake CSS @import directives and HTML comments. Zimbra’s sanitizer strips the @import fragments, but the remaining characters reassemble into executable JavaScript.

Proofpoint tracks this JavaScript payload as ZimReaper. Once executed inside the authenticated webmail session, the payload performs the following actions:

  • Steals the CSRF token and autofilled browser password
  • Extracts two-factor authentication scratch codes via internal APIs
  • Harvests the Global Address List by brute-forcing two-character queries
  • Exfiltrates the last 90 days of emails as compressed TGZ archives
  • Creates an application-specific password named “ZimbraWeb” to bypass MFA

Exfiltration occurs over both DNS and HTTPS. Smaller data is encoded into DNS A-record lookups to actor-controlled domains, while larger payloads are uploaded directly over HTTPS. In addition, Palo Alto Networks Unit 42 observed at least nine C2 IP addresses and nine domains associated with this campaign, with each server remaining active for an average of 35 days.

Business and Operational Impact

The impact of this campaign extends beyond simple email theft. Organizations running unpatched Zimbra instances face persistent compromise of their entire email infrastructure. Therefore, the following consequences are significant:

  • Credential and MFA Bypass: Stolen passwords and scratch codes enable ongoing access even after patching
  • Global Address List Exposure: Attackers gain a complete map of organizational contacts for follow-on targeting
  • Historical Mail Compromise: Ninety days of email content provides intelligence value for espionage and business email compromise
  • Lateral Movement: Compromised mail accounts can be used for further phishing or access to linked cloud services
  • Supply Chain Risk: Compromised organizations may unknowingly forward exploit emails from trusted internal addresses

Targeted sectors include Defense Industrial Base organizations, federal and local government, education, energy, law enforcement, media, non-governmental organizations, and technology firms across NATO member states and Ukraine.

Mitigation and Recommendations

Immediate Actions for Zimbra Administrators

  1. Upgrade Zimbra Collaboration Suite to version 10.1.13 or later immediately. Note that Zimbra 10.0 reached end of life on December 31, 2025, and should be migrated to 10.1.
  2. Review /opt/zimbra/log/audit.log for calls to CreateAppSpecificPassword and remove any credential named “ZimbraWeb”
  3. Audit accounts where zimbraPrefImapEnabled is set to TRUE without legitimate business need
  4. Monitor for SOAP calls to GetScratchCodesRequest, which should be rare in normal operation
  5. Filter DNS queries for known C2 domains and alert on long random subdomain lookups indicative of DNS exfiltration

Account Remediation for Potentially Compromised Mailboxes

  1. Reset passwords for any mailbox that opened or previewed a suspicious message in the Classic UI
  2. Invalidate all active Zimbra sessions for affected accounts
  3. Regenerate two-factor authentication scratch codes
  4. Delete any application-specific passwords created without authorization

Additional Defensive Measures

CISA recommends implementing phishing-resistant multi-factor authentication where possible. Also, organizations should consider migrating away from the Classic Web Client if feasible. In addition, monitoring email gateways for messages containing fragmented @import CSS patterns can help detect exploit payloads. Proofpoint has published a YARA rule to match these patterns.

Bottom line: Patching Zimbra stops the next exploit from running, but it does not revoke credentials already stolen. Account remediation is equally important as the patch itself.

Incident Summary

CVE ID / Incident: CVE-2025-66376 (Zimbra Collaboration Suite XSS)
Threat Actor: LAUNDRY BEAR / Void Blizzard (Russian state-sponsored APT)
Affected Systems: Zimbra Collaboration Suite 10.0 before 10.0.18 and 10.1 before 10.1.13
Disclosure Date: July 23, 2026 (joint CISA/NSA advisory)
Patch Status: Available since November 6, 2025; additional XSS fixes in 10.1.20 (July 20, 2026)
Exploitation Vector: Zero-click stored XSS via crafted HTML email in Classic Web Client
Data Exfiltrated: 90 days of emails, GAL, passwords, 2FA tokens, application passcodes

References

  1. CISA, NSA, FBI, et al., “Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite,” Cybersecurity Advisory AA26-204A, July 23, 2026, https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a
  2. BleepingComputer, “Russian hackers exploit Zimbra zero-click flaw for email theft,” Lawrence Abrams, July 23, 2026, https://www.bleepingcomputer.com/news/security/russian-hackers-exploit-zimbra-zero-click-flaw-for-email-theft/
  3. The Hacker News, “Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes,” July 23, 2026, https://thehackernews.com/2026/07/russian-espionage-group-exploited.html
  4. Palo Alto Networks Unit 42, “Russian Webmail Espionage: CL-STA-1114 Activity,” July 2026, https://unit42.paloaltonetworks.com/russian-webmail-espionage/
  5. Proofpoint, “TA488 Targets Zimbra Mailservers with Half-Click Exploits,” July 2026, https://www.proofpoint.com/us/blog/threat-insight/ta488-targets-zimbra-mailservers-half-click-exploits
  6. National Security Agency, “NSA and Partners Alert Zimbra Collaboration Suite Users of a Russian State-Supported Phishing Campaign,” Press Release, July 23, 2026, https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/4553352/

Tags:

CVEIncidentPhishing
Author

ogwatermelon

Follow Me
Other Articles
Previous

South Korea Diplomat Data Breach

Next

XBOW Bing Images RCE: SVG Command Injection Yields SYSTEM Shells

AI Botnet Breach CVE Exploit Hack Incident Infostealer Linux Mac Malware Network Phishing Ransomware RCE supply chain Vishing Vulnerability Windows World Zero Day

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026

Categories

  • AI
  • BotNet
  • Breach
  • CVE
  • exploit
  • Hack
  • Incident
  • Infostealer
  • Linux
  • Mac
  • Malware
  • Phishing
  • Ransomware
  • RCE
  • supply-chain
  • Uncategorized
  • Vishing
  • Vulnerability
  • Windows
  • World
  • Zero Day
Copyright 2026 — The Cybersecurity Focus. All rights reserved.