CVE-2025-66376Active Exploitation(synacor / zimbra_collaboration_suite)

CRITICALCVSS 6.1 · MEDIUMCISA KEV

Exploitation observed; activity peaked at 25 mentions and remains active

Immediate actions

  • Patch synacor zimbra_collaboration_suite systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.

8.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-04-01. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-79

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • zimbra_collaboration_suite

Threat summary

  • Active exploitation appears in 96 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 108 mentions across 17 observed days

What's happening

  • Active exploitation reported across 96 signals
  • Exploit tool or code specified in 5 signals
  • PoC mentioned or linked in 5 signals
  • Patch or workaround mentioned in 43 signals
  • Technical details provided in 75 signals
  • Disclosure: 5 classified signals
  • General: 5 classified signals
  • Peaked 6d ago at 25 mentions (2026-07-24); latest day: 1
  • 108 total mentions across 17 days

Affected systems

Vendors
Products
zimbra_collaboration_suite

Deep dive

Activity timeline108 mentions / 17d
06131925Mentions · 2026-03-18: 13Mentions · 2026-03-19: 24Mentions · 2026-03-20: 8Mentions · 2026-03-21: 4Mentions · 2026-03-22: 3Mentions · 2026-03-23: 2Mentions · 2026-03-25: 1Mentions · 2026-03-26: 1Mentions · 2026-04-03: 1Mentions · 2026-07-23: 10Mentions · 2026-07-24: 25Mentions · 2026-07-25: 7Mentions · 2026-07-26: 2Mentions · 2026-07-27: 3Mentions · 2026-07-28: 2Mentions · 2026-08-17: 1Mentions · 2026-08-19: 1PoC Mentioned / Linked · 2026-07-24: 4PoC Mentioned / Linked · 2026-07-25: 1Exploit Tool / Code · 2026-07-24: 3Exploit Tool / Code · 2026-07-26: 1Exploit Tool / Code · 2026-07-28: 1Active Exploitation · 2026-03-18: 10Active Exploitation · 2026-03-19: 21Active Exploitation · 2026-03-20: 6Active Exploitation · 2026-03-21: 4Active Exploitation · 2026-03-22: 3Active Exploitation · 2026-03-23: 2Active Exploitation · 2026-03-26: 1Active Exploitation · 2026-07-23: 10Active Exploitation · 2026-07-24: 24Active Exploitation · 2026-07-25: 6Active Exploitation · 2026-07-26: 2Active Exploitation · 2026-07-27: 3Active Exploitation · 2026-07-28: 2Active Exploitation · 2026-08-17: 1Active Exploitation · 2026-08-19: 1Patch / Workaround · 2026-03-18: 7Patch / Workaround · 2026-03-19: 10Patch / Workaround · 2026-03-20: 2Patch / Workaround · 2026-03-21: 2Patch / Workaround · 2026-07-23: 3Patch / Workaround · 2026-07-24: 11Patch / Workaround · 2026-07-25: 4Patch / Workaround · 2026-07-26: 1Patch / Workaround · 2026-07-27: 1Patch / Workaround · 2026-07-28: 2Technical Details · 2026-03-18: 12Technical Details · 2026-03-19: 20Technical Details · 2026-03-20: 8Technical Details · 2026-03-21: 3Technical Details · 2026-03-22: 3Technical Details · 2026-03-23: 1Technical Details · 2026-03-26: 1Technical Details · 2026-07-23: 4Technical Details · 2026-07-24: 14Technical Details · 2026-07-25: 3Technical Details · 2026-07-26: 2Technical Details · 2026-07-27: 1Technical Details · 2026-07-28: 2Technical Details · 2026-08-19: 103-1803-1903-2003-2103-2203-2303-2503-2604-0307-2307-2407-2507-2607-2707-2808-1708-19
Signal classification5 categories
Active Exploitation
9285.2%
Disclosure
54.6%
General
54.6%
Patch
54.6%
Exploit
10.9%
Referenced assets75 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-1813
Active Exploitation9Disclosure1General1Patch2
2026-03-1924
Active Exploitation21Disclosure1General1Patch1
2026-03-208
Active Exploitation5Disclosure2General1
2026-03-214
Active Exploitation4
2026-03-223
Active Exploitation3
2026-03-232
Active Exploitation2
2026-03-251
General1
2026-03-261
Active Exploitation1
2026-04-031
Disclosure1
2026-07-2310
Active Exploitation9Patch1
2026-07-2425
Active Exploitation23Exploit1Patch1
2026-07-257
Active Exploitation6General1
2026-07-262
Active Exploitation2
2026-07-273
Active Exploitation3
2026-07-282
Active Exploitation2
2026-08-171
Active Exploitation1
2026-08-191
Active Exploitation1
Full discourse20 posts
  • Sathwik Ram Prakki@PrakkiSathwik
    Active Exploitation

    New Research! Operation #GhostMail #APT28 (FancyBear) targets the Ukrainian State Hydrology Agency, exploiting a stored XSS vulnerability (CVE-2025-66376) in Zimbra Classic UI to deploy a browser-resident stealer similar to #SpyPress, that exfiltrates data over both DNS & HTTPS https://t.co/zO4fPuuuns

    Post summary

    The tweet reports that APT28 is actively exploiting CVE‑2025‑66376 (a stored XSS in Zimbra Classic UI) to deploy a browser‑resident data stealer.

    119170335.8K
    1.6K followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🚨 Russian state-supported threat group "LAUNDRY BEAR" is exploiting CVE-2025-66376 to compromise Zimbra Collaboration Suite (ZCS) software—just viewing a malicious email in a vulnerable webmail version can lead to data exfiltration. Patch ZCS now 👉 https://go.dhs.gov/5dt https://t.co/hZFVquwzYf

    Post summary

    The tweet asserts that the Russian-backed group LUNDRY BEAR is actively exploiting CVE‑2025‑66376 against Zimbra Collaboration Suite, with exploitation triggered by viewing malicious email, and urges users to apply the available patch.

    5182701212.8K
    302.2K followersView on X
  • Virus Bulletin@virusbtn
    Active Exploitation

    Proofpoint uncovered that Russia-aligned threat actor TA488 (Void Blizzard, Laundry Bear) was exploiting a previously unknown vulnerability against Zimbra mailservers for at least five months during 2025, until the issue was patched with CVE-2025-66376. https://www.proofpoint.com/us/blog/threat-insight/ta488-targets-zimbra-mailservers-half-click-exploits https://t.co/CueIfb7SeZ

    Post summary

    Proofpoint reports that the threat actor TA488 actively exploited a previously unknown Zimbra mailserver vulnerability for at least five months in 2025, until a patch was applied.

    0121301119.4K
    61.5K followersView on X
  • Greg Lesnewich@greglesnewich
    Active Exploitation

    Let’s talk reporting with the NSA and the FBI and friends TA488 used CVE-2025-66376 for 5 months as a zero day, and for a few months after, to target education, gov, and nuclear entities in the US and Ukraine. reports here: https://www.proofpoint.com/us/blog/threat-insight/ta488-targets-zimbra-mailservers-half-click-exploits https://media.defense.gov/2026/Jul/22/2003965244/-1/-1/1/CSA_RUSSIA_PHISHING_TARGET_ZIMBRA.PDF

    Post summary

    TA488 was actively exploiting CVE-2025‑66376 against education, government, and nuclear targets in the US and Ukraine for several months, with external reports referenced for further detail.

    112028112.1K
    3.9K followersView on X
  • blackorbird@blackorbird
    Disclosure

    #APT28 + CVE-2025-66376 Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message. https://www.seqrite.com/blog/operation-ghostmail-zimbra-xss-russian-apt-ukraine/ https://t.co/C7K8rwpciT

    Post summary

    CVE‑2025‑66376 is a stored XSS flaw in legacy Zimbra Collaboration Classic UI that permits attackers to insert CSS @import directives in HTML e‑mail messages; no PoC, exploit code, or patch is referenced, and no active exploitation claims are made.

    09020152.4K
    40.7K followersView on X
  • Cyber_OSINT@Cyber_O51NT
    Active Exploitation

    US agencies warn Laundry Bear exploited CVE-2025-66376 to silently steal emails from unpatched Zimbra servers via zero-click JavaScript in malicious emails, with guidance to patch, monitor, and enforce MFA. https://securityaffairs.com/195901/apt/us-agencies-warn-of-laundry-bear-campaign-targeting-unpatched-zimbra-servers.html

    Post summary

    US agencies warn that Laundry Bear is exploiting CVE-2025-66376 in unpatched Zimbra servers via a zero‑click JavaScript attack to steal emails; immediate patching and MFA enforcement are recommended.

    1722665.2K
    22.8K followersView on X
  • Dark Web Informer@DarkWebInformer
    Active Exploitation

    ‼️CISA has added 2 vulnerabilities to the KEV Catalog https://darkwebinformer.com/cisa-kev-catalog/ CVE-2025-66376: Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability. CVSS: 7.1 CVE-2026-20963: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability. CVSS: 8.8

    Post summary

    CISA has added CVE‑2025‑66376 and CVE‑2026‑20963 to its KEV catalog, indicating these vulnerabilities are currently being exploited in the wild, and it provides brief technical details including type and CVSS scores.

    1501764.6K
    174.6K followersView on X
  • Hunt.io@Huntio
    Active Exploitation

    🚨 Laundry Bear Targets US and Ukraine Through Zimbra https://www.darkreading.com/cyberattacks-data-breaches/russian-hackers-zimbra-zero-day-us-ukraine-targets Russian state-backed group Laundry Bear is exploiting the Zimbra zero-day CVE-2025-66376 to target US and Ukrainian government, defense, and scientific organizations. The attack doesn't require victims to open an attachment or follow a link. Simply opening or previewing an email in a vulnerable Zimbra webmail client could trigger a malicious JavaScript payload. The exploit collects up to 90 days of emails and data, then sends everything to attacker-controlled infrastructure. Zimbra patched the flaw last year, but unpatched servers remain exposed. #ThreatIntel #LaundryBear #Zimbra #CyberSecurity

    Post summary

    Russian state‑backed group Laundry Bear is actively exploiting Zimbra CVE‑2025‑66376 via malicious JavaScript in email previews, harvesting up to 90 days of emails, even though a patch was released last year.

    1101861.4K
    7.1K followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️ We added Synacor Zimbra Collaboration Suite (ZCS) cross-site scripting vulnerability CVE-2025-66376 to our KEV Catalog. Visit https://go.dhs.gov/Z3Q for more information. #Cybersecurity #InfoSec https://t.co/GbvwRmJfCG

    Post summary

    The snippet announces that CVE‑2025‑66376, a cross‑site scripting flaw in Synacor Zimbra Collaboration Suite, has been added to the DHS KEV catalog, indicating its active exploitation in the wild.

    0801414.1K
    293.1K followersView on X
  • yousukezan@yousukezan
    Active Exploitation

    Zimbraの脆弱性が悪用され、メールを開くだけで情報が盗まれる攻撃が確認された。HTMLメールに仕込まれたスクリプトが動作し、政府機関を狙う高度なスパイ活動に発展している。 問題はCVE-2025-66376として追跡されるXSS脆弱性で、Zimbra Classic UIにおけるHTMLメール処理の不備に起因する。攻撃者はCSSの@importを悪用し、メール閲覧時にJavaScriptを実行させることでアカウントを乗っ取る。影響はセッション情報や認証情報に及び、環境全体の侵害につながる恐れがある。 この攻撃はロシア系APT28とみられ、ウクライナ政府機関を標的に展開された。インターン応募を装うメールで不正コードを埋め込み、認証情報や2FAコード、メール内容を最大90日分窃取する。データはDNSやHTTPSを通じて外部へ送信され、持続的な監視も可能となる。 当該脆弱性はKEVにも追加され、修正はZimbra 10.1.13および10.0.18で提供されている。迅速な更新が求められる。 https://securityaffairs.com/189673/security/russian-apt-targets-ukraine-via-zimbra-xss-flaw-cve-2025-66376.html

    Post summary

    CVE-2025-66376, an XSS flaw in Zimbra Classic UI, is being actively exploited by APT28 against Ukrainian government agencies, stealing credentials and enabling persistent monitoring, while patches have been released in Zimbra 10.1.13 and 10.0.18.

    020951.8K
    12.0K followersView on X
  • Pierluigi Paganini - Security Affairs@securityaffairs
    Active Exploitation

    Russian #APT targets Ukraine via #Zimbra XSS flaw CVE-2025-66376 https://securityaffairs.com/189673/hacking/russian-apt-targets-ukraine-via-zimbra-xss-flaw-cve-2025-66376.html #securityaffairs #hacking #Russia @Seqrite

    Post summary

    The tweet reports that Russian APTs are exploiting a Zimbra XSS flaw (CVE‑2025‑66376) to target Ukraine, indicating active exploitation, but it lacks details on PoC, exploit code, patches, or deeper technical specifics.

    14071434
    37.5K followersView on X
  • Gray Hats@the_yellow_fall
    Active Exploitation

    CISA adds actively exploited Microsoft SharePoint RCE (CVE-2026-20963) and Zimbra XSS (CVE-2025-66376) to its KEV catalog. Update your systems immediately. #CISA #KEVCatalog #SharePoint #Zimbra #CyberSecurity #InfoSec #CVE #RCE #Vulnerability #PatchAlert https://securityonline.info/exploited-in-wild-cisa-kev-catalog-sharepoint-zimbra-vulnerabilities/ https://t.co/naJO9wRcWF

    Post summary

    CISA reports that Microsoft SharePoint RCE CVE‑2026‑20963 and Zimbra XSS CVE‑2025‑66376 are actively exploited, urging immediate system updates.

    03162821
    10.7K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(3/18追加) 🛡️No.1545 CVE-2025-66376 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability ✅概要 ・深刻度:重要⚠️ 7.2 (CVSS Base) / MITRE (CNA) ・種別:クロスサイトスクリプティング (CWE-79) ・CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N Synacor Zimbra Collaboration Suite (ZCS) におけるクロスサイトスクリプティング(XSS)の脆弱性。 細工されたコンテンツ(メールやリンク等)をユーザーに閲覧させることで、ブラウザ上で任意のスクリプトが実行される可能性がある。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ✅攻撃前提条件 ・攻撃者が細工したコンテンツ(メール・URL等)を被害者に閲覧させること ・標的が Zimbra Web UI を使用していること ・標的がログイン済みであること ✅悪用時影響 ・セッション情報の窃取 ・ユーザーアカウントの乗っ取り ・メール内容の不正取得・送信 ・フィッシングやマルウェア配布の踏み台化 ✅悪用事例等に関する公開情報 ・PoC/Exploit:確認できず ・ITW:確認できず(2026/03時点) ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-66376 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66376 https://www.zimbra.com/security-advisories/ https://www.cisa.gov/news-events/alerts/2026/03/18/cisa-adds-one-known-exploited-vulnerability-catalog #vulnerability

    Post summary

    CISA confirmed CVE-2025-66376 is being exploited and added it to its KEV catalog, though no public PoC or exploit code exists; technical details of the XSS vulnerability are documented but no patch or workaround is mentioned.

    011904.3K
    42.8K followersView on X
  • The Cyber Security Hub™@TheCyberSecHub
    Active Exploitation

    Russian hackers exploit unpatched Zimbra servers to steal emails https://www.helpnetsecurity.com/2026/07/24/laundry-bear-zimbra-vulnerability-cve-2025-66376/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    Russian hackers are actively exploiting an unpatched Zimbra server (CVE‑2025‑66376) to steal emails, demonstrating ongoing exploitation activity in the wild.

    020402.1K
    195.0K followersView on X
  • Elite Cyber Intelligence Solutions@crygma
    Active Exploitation

    Void Blizzard Targets European Cloud Infrastructure via Critical Zimbra Vulnerability CVE-2025-66376 | Encrygma — AI Cyber Security Intelligence https://encrygma.com/articles/void-blizzard-targets-european-cloud-infrastructure-via-critical-zimbra-vulnerab

    Post summary

    Void Blizzard is reported to be actively exploiting CVE‑2025‑66376 against European cloud infrastructure; the article offers no PoC, exploit code, patch detail, or in‑depth technical description.

    0203046
    80 followersView on X
  • eSecurityPlanet@eSecurityPlanet
    Active Exploitation

    Attackers are finding more ways in. 🚨 🤖 AI/LLM tool exposures jumped 60% in nine months, expanding attack surfaces. 🎯 TA488 exploited Zimbra CVE-2025-66376 in attacks on government mail servers. Validate internet-facing assets and patch critical vulnerabilities. https://t.co/pwd1oc42rg

    Post summary

    The tweet announces that attackers (TA488) have actively exploited Zimbra CVE-2025-66376 against government mail servers, urging organizations to patch critical vulnerabilities.

    11030325
    6.8K followersView on X
  • SafeBreach@safebreach
    Active Exploitation

    🚨 New SafeBreach Labs Coverage CISA Alert AA26-204A details how Russian APT LAUNDRY BEAR exploits CVE-2025-66376 to target unpatched Zimbra servers. See the latest TTPs and how to validate your defenses. 🔗 https://hubs.ly/Q04qCGZG0 https://t.co/6zI62irYNR

    Post summary

    The tweet confirms that the Russian APT LAUNDRY BEAR is actively exploiting CVE-2025-66376 against unpatched Zimbra servers, as reported by CISA.

    00050172
    2.5K followersView on X
  • SOCRadar®@socradar
    Active Exploitation

    A stored XSS flaw in webmail = a VIP pass to your inbox. ✉️💥 CVE-2025-66376 in Zimbra Collaboration Suite was exploited as a zero-day by Russian APT LAUNDRY BEAR (aka Void Blizzard). It allows attackers to steal mailboxes and hijack active sessions. We broke down the root cause, PoC status, and how to mitigate the risk and strengthen your posture. 👇 🔗 https://hubs.la/Q04qJYXT0 #CyberSecurity #Zimbra #ThreatIntel #VulnerabilityManagement

    Post summary

    Zimbra Collaboration Suite’s CVE-2025‑66376 is a stored XSS vulnerability that has already been exploited by the Russian APT group LaunaDream Bear, enabling mailbox theft and session hijacking. The post outlines PoC status and mitigation but lacks code or patch details.

    00031918
    7.1K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    Russian 🇷🇺 state-sponsored group Laundry Bear exploited Zimbra CVE-2025-66376 as a zero-day since July 2025, targeting Western government, defense, and critical infrastructure via zero-click email to steal credentials and 2FA tokens. Key findings: - CVE-2025-66376 is a CSS @import sanitization flaw in ZCS. Laundry Bear weaponized it months before NVD publication on Jan. 5, 2026. Payload is Base64-encoded JavaScript hidden in an SVG onload attribute, XOR-obfuscated to rotate signatures easily. Victim only needs to view the email; no click required. - The custom tool "Ulej" executes 12 async exfiltration stages: harvests email address via Zimbra SOAP, injects hidden login fields to trigger password manager autofill, steals 2FA scratch codes, and creates app-specific IMAP passwords to maintain persistent mailbox access that bypasses MFA entirely. All exfil over HTTPS, no DNS. - Stolen data stages to actor-controlled VPS running "Flowerbed," Laundry Bear's collection framework, before onward exfiltration to internal infrastructure. Phishing emails originate from previously compromised accounts to evade anti-phishing controls. - Patch immediately: CVE-2025-66376 is fixed in ZCS 10.1.13 and 10.0.18. If patching is blocked, abandon the Classic webmail client now. Monitor for newly created app-specific IMAP passwords and unexpected IMAP sessions as a key post-compromise indicator. Full IOC list and mitigation guidance are in the joint CISA/NSA/FBI advisory. #DFIR_Radar

    Post summary

    Russian state‑sponsored group Laundry Bear has been using the CVE‑2025‑66376 zero‑day in Zimbra since July 2025, leveraging a custom Ulej tool to exfiltrate credentials and 2FA tokens via a zero‑click SVG payload. Immediate patching to ZCS 10.1.13/10.0.18 and monitoring of app‑specific IMAP passwords and abnormal sessions is urged.

    20010402
    1.8K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    CVE-2025-66376 (CVSS 6.1): Russian 🇷🇺 APT LAUNDRY BEAR exploited a Zimbra stored-XSS zero-day for mailbox theft across Western government and commercial targets, active since at least July 2025 and listed in CISA KEV. - CVE-2025-66376 is a stored XSS (CWE-79) in Zimbra Classic UI's HTML email renderer. No link click required: viewing the message executes attacker-controlled JavaScript in the authenticated session. Root cause is incomplete sanitization of CSS @import directives combined with SVG-based event handlers and fragmented tag-split markup. Affects Zimbra 10.0 before 10.0.18 and 10.1 before 10.1.13. Patch shipped November 2025; CISA KEV-listed March 18, 2026. - The script ran inside the victim's session and exfiltrated recent email (90 days), Global Address List, 2FA scratch codes, browser-saved credentials, and newly created application passcodes. Data left via DNS exfiltration to d-{ID}.{type}.{base32data}.i.{domain}/pixel.gif and HTTPS to js-{ID}.i.{domain}/v/p. Flowerbed framework infrastructure includes zmailanalytics[.]com (216.252.238[.]104), zimbrastat[.]com (64.226.124[.]190), and synacorzimbra[.]nl (216.252.238[.]64). - Key post-compromise artifacts: CreateAppSpecificPasswordRequest events in /opt/zimbra/log/mailbox.log with passcode named ZimbraWeb are near-certain indicators of compromise. Also hunt GetScratchCodesRequest bursts and SearchGalRequest spikes. #DFIR_Radar

    Post summary

    The post reports active exploitation of CVE‑2025‑66376 in Zimbra by APT LAUNDRY BEAR, detailing the attack, impact, and patch status.

    10020295
    1.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsynacorzimbra_collaboration_suite---

Explore more