socradar.io 7/25/2026, 10:21:25 AM · external

Zimbra XSS bug CVE‑2025-66376 lets Russian hackers steal mail

Zimbra XSS bug CVE‑2025-66376 lets Russian hackers steal mail
Developing story campaign 7 articles tracked
Russian Laundry Bear exploits Zimbra XSS flaw CVE-2025-66376
CyberSIXT Evidence Panel
Primary Source media.defense.gov
CISA KEV Listed in KEV
Patch Patch Available
Threat Actor
🇷🇺 Void Blizzard

CVE- 2025-66376 is a stored cross-site scripting (XSS) vulnerability in the Zimbra Collaboration Suite's Classic UI, allowing mailbox theft through malicious emails. Exploitation requires the targeted user to view an email containing crafted HTML without clicks or attachments. The flaw affects Zimbra versions 10.0 before 10.0.18 and 10.1 before 10.1.13. Russian state-sponsored actors, notably LAUNDRY BEAR, actively exploited this zero-day before fixes were released in November 2025.

The vulnerability could expose sensitive data from compromised mailboxes, emphasizing the need for urgent patching and incident response strategies. Organizations should immediately upgrade to a fixed version or limit the use of the Classic UI to mitigate risks. Detection efforts should focus on reviewing logs for unusual activity and searching for suspicious email content.

View Primary Source Via socradar.io

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline