CISA Warns on CVE-2025-66376 in Zimbra
CISA, NSA and FBI warned on a Zimbra flaw abused by LAUNDRY BEAR to steal email, 2FA codes and passwords with a single message.
CISA, NSA, FBI and international partners released a joint advisory on LAUNDRY BEAR, a Russian state-sponsored group that is exploiting a stored cross-site scripting flaw in Zimbra Collaboration Suite to steal email, 2FA codes and application passwords by opening a malicious email.
Joint advisory on Zimbra
CISA, NSA, FBI and international partners issued a joint advisory on LAUNDRY BEAR, a Russian state-sponsored group, over a campaign abusing a stored cross-site scripting flaw in Zimbra Collaboration Suite tracked as CVE-2025-66376.
According to the notice, the technique can steal email, two-factor authentication codes and application passwords simply by opening a malicious message. The group targets Zimbra users through that initial interaction, with no further action required from the victim beyond viewing the email.
Flaw patched months before the alert
Zimbra patched the vulnerability on Nov. 6, 2025, months after active exploitation had already begun. CISA added CVE-2025-66376 to its Known Exploited Vulnerabilities catalog, or KEV, on March 18, 2026.
The Hacker News also reported that the attack automatically collects the victim's last 90 days of email. That broadens the scope of the intrusion because it is not limited to what is open at the time, but can pull part of the mailbox's recent history.
The combination of active exploitation, email access and credential theft makes this flaw a significant risk for organizations using Zimbra Collaboration Suite that have not yet applied the vendor patch.
Sources
- Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codesthehackernews.com· The Hacker News
- Russian hackers exploit Zimbra zero-click flaw for email theftbleepingcomputer.com· BleepingComputer
- CISA, NSA, FBI and Partners Warn Zimbra Collaboration Suite Users of Ongoing Russian State-Supported Malicious Threat Activitycisa.gov· CISA



