CVE- 2025-66376 is a stored cross-site scripting (XSS) vulnerability in the Zimbra Collaboration Suite's Classic UI, allowing mailbox theft through malicious emails. Exploitation requires the targeted user to view an email containing crafted HTML without clicks or attachments. The flaw affects Zimbra versions 10.0 before 10.0.18 and 10.1 before 10.1.13. Russian state-sponsored actors, notably LAUNDRY BEAR, actively exploited this zero-day before fixes were released in November 2025.
The vulnerability could expose sensitive data from compromised mailboxes, emphasizing the need for urgent patching and incident response strategies. Organizations should immediately upgrade to a fixed version or limit the use of the Classic UI to mitigate risks. Detection efforts should focus on reviewing logs for unusual activity and searching for suspicious email content.