CiberLATAMbywhalemate

CISA Warns on CVE-2025-66376 in Zimbra

CISA, NSA and FBI warned on a Zimbra flaw abused by LAUNDRY BEAR to steal email, 2FA codes and passwords with a single message.

Whalemate Labs · AI-assisted researchPublished:1 min read

CISA, NSA, FBI and international partners released a joint advisory on LAUNDRY BEAR, a Russian state-sponsored group that is exploiting a stored cross-site scripting flaw in Zimbra Collaboration Suite to steal email, 2FA codes and application passwords by opening a malicious email.

Joint advisory on Zimbra

CISA, NSA, FBI and international partners issued a joint advisory on LAUNDRY BEAR, a Russian state-sponsored group, over a campaign abusing a stored cross-site scripting flaw in Zimbra Collaboration Suite tracked as CVE-2025-66376.

According to the notice, the technique can steal email, two-factor authentication codes and application passwords simply by opening a malicious message. The group targets Zimbra users through that initial interaction, with no further action required from the victim beyond viewing the email.

Flaw patched months before the alert

Zimbra patched the vulnerability on Nov. 6, 2025, months after active exploitation had already begun. CISA added CVE-2025-66376 to its Known Exploited Vulnerabilities catalog, or KEV, on March 18, 2026.

The Hacker News also reported that the attack automatically collects the victim's last 90 days of email. That broadens the scope of the intrusion because it is not limited to what is open at the time, but can pull part of the mailbox's recent history.

The combination of active exploitation, email access and credential theft makes this flaw a significant risk for organizations using Zimbra Collaboration Suite that have not yet applied the vendor patch.

Sources

View all