blackorbird[verified]@blackorbirdDisclosure
CVE‑2025‑66376 is a stored XSS flaw in legacy Zimbra Collaboration Classic UI that permits attackers to insert CSS @import directives in HTML e‑mail messages; no PoC, exploit code, or patch is referenced, and no active exploitation claims are made.
Hunt.io[verified]@HuntioActive Exploitation
Russian state‑backed group Laundry Bear is actively exploiting Zimbra CVE‑2025‑66376 via malicious JavaScript in email previews, harvesting up to 90 days of emails, even though a patch was released last year.
yousukezan[verified]@yousukezanActive Exploitation
CVE-2025-66376, an XSS flaw in Zimbra Classic UI, is being actively exploited by APT28 against Ukrainian government agencies, stealing credentials and enabling persistent monitoring, while patches have been released in Zimbra 10.1.13 and 10.0.18.
piyokango[verified]@piyokangoActive Exploitation
CISA confirmed CVE-2025-66376 is being exploited and added it to its KEV catalog, though no public PoC or exploit code exists; technical details of the XSS vulnerability are documented but no patch or workaround is mentioned.
The Cyber Security Hub™[verified]@TheCyberSecHubActive Exploitation
Russian hackers are actively exploiting an unpatched Zimbra server (CVE‑2025‑66376) to steal emails, demonstrating ongoing exploitation activity in the wild.
Elite Cyber Intelligence Solutions[verified]@crygmaActive Exploitation
Void Blizzard is reported to be actively exploiting CVE‑2025‑66376 against European cloud infrastructure; the article offers no PoC, exploit code, patch detail, or in‑depth technical description.
SOCRadar®[verified]@socradarActive Exploitation
Zimbra Collaboration Suite’s CVE-2025‑66376 is a stored XSS vulnerability that has already been exploited by the Russian APT group LaunaDream Bear, enabling mailbox theft and session hijacking. The post outlines PoC status and mitigation but lacks code or patch details.
DFIR Radar[verified]@DFIR_RadarActive Exploitation
Russian state‑sponsored group Laundry Bear has been using the CVE‑2025‑66376 zero‑day in Zimbra since July 2025, leveraging a custom Ulej tool to exfiltrate credentials and 2FA tokens via a zero‑click SVG payload. Immediate patching to ZCS 10.1.13/10.0.18 and monitoring of app‑specific IMAP passwords and abnormal sessions is urged.