INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Zimbra XSS Flaw Exploits Microsoft SharePoint Vulnerability

| 2026-03-19 14:48 CRITICAL HIGH
Executive Summary AI-generated
Russian APTs have been exploiting a high-severity XSS vulnerability in Zimbra Collaboration, tracked as CVE-2025-66376. This attack leverages insufficiently sanitized HTML emails to run scripts when opened, targeting users in Ukraine. The threat actor is linked to Russia-linked groups such as APT28 (aka UAC-0001), Fancy Bear, Pawn Storm, Sofacy Group, Sednit, BlueDelta, and STRONTIUM. The campaign has been attributed with a phishing email that appears legitimate, using a compromised student account to target Ukraine's State Hydrology Agency. This attack differs from previous ones in its use of an HTML email XSS payload, dual-channel exfiltration, and structured SOAP API abuse. US CISA has added the flaw CVE-2025-66376 to its Known Exploited Vulnerabilities catalog, ordering federal agencies to address it by April 1st, 2026.
Technical Mitigations AI-generated
* Implement secure email filtering and content inspection: Use email security solutions that can detect and block malicious emails, such as SPF, DKIM, and DMARC, to prevent phishing attacks. * Regularly update and patch Zimbra Collaboration Suite (ZCS): Ensure all Zimbra installations are up-to-date with the latest patches and updates from Synacor and Microsoft to fix known vulnerabilities like CVE-2025-66376. * Use a web application firewall (WAF) or intrusion detection system: Install a WAF or IDS to detect and block suspicious traffic, reducing the risk of exploitation by attackers. * Implement multi-factor authentication (MFA): Require users to authenticate with MFA, such as two-factor authentication (2FA), to prevent unauthorized access even if an attacker gains access through phishing or other means.
Technical Observables
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence distributed on:
Incident Link
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation GhostMailOperation GhostMailOperation RoundPressOperation RoundPress APT28APT28APT29APT29Winter VivernWinter Vivern SednitSednitSofacySofacy CVE-2026-2096CVE-2026-2096 CVE-2026-20963CVE-2026-20963 CVE-2025-66376CVE-2025-66376 CVE-2026-20131CVE-2026-20131 CVE-2025-27915CVE-2025-27915
Target & Sectors
NORTH_AMERICA NORTH_AMERICA maritimemaritime defensedefense healthhealth governmentgovernment manufacturingmanufacturing educationeducation
Incident Timeline
November 2021
Threat actors exploited a Zimbra XSS vulnerability CVE-2025-66376 to target Ukrainian agencies.
attribution the Binding Operational Directive (
June 2022
Threat actors exploited a previously unknown Remote Code Execution vulnerability in Zimbra, allowing them to breach over 1,000 servers.
tactic Remote Code Execution
infrastructure 1,000 servers
September 2022
Hackers exploited a zero-day vulnerability in Zimbra Collaboration Suite to breach nearly 900 Ukrainian servers via an XSS flaw.
tactic Remote Code Execution
infrastructure 900 servers
September 2024
Threat actors used a Zimbra XSS flaw CVE-2025-66376 to target Ukrainian organizations via the Interlock ransomware operation.
tactic Ransomware
organisation ClickFix
November 2025
Russian APT actors exploited a Zimbra XSS flaw CVE-2025-66376 in versions 10.0.18 and 10.1.13 to target Ukraine.
infrastructure 10.1.13
infrastructure 10.0.18
vulnerability CVE-2026-20963
infrastructure 8.8
general_metric 8.8 Fixed CVE-2026 CVSS score
20 Jan 2026
Russian APTs targeted Ukraine via Zimbra XSS flaw CVE-2025-66376, setting up C2 infrastructure on domains js-l1wt597cimk[.]i[.]zimbrasoft[.]com[.]ua and js-26tik3egye4[.]i[.]zimbrasoft[.]com[.]ua.
source_region Russian Federation
threat_actor APT28
tactic Phishing
tactic Exfiltration
organisation Cozy Bear
threat_actor APT29
threat_actor Winter Vivern
January 22, 2026
The National Academy of Internal Affairs was targeted by Russian APT actors via exploitation of a Zimbra XSS vulnerability CVE-2025-66376.
organisation the National Academy of Internal Affairs
January 22
Threat actors exploited a Zimbra XSS vulnerability CVE-2025-66376 to compromise the email accounts of a national maritime agency on January 22.
industry Maritime
January 2026
Russian APT actors exploited a Zimbra XSS flaw CVE-2025-66376 to target Ukraine in January 2026.
Jan 2026
Threat actors used a Zimbra XSS flaw CVE-2025-66376 to target Ukrainian government entities.
threat_actor APT28
organisation SpyPress
January 26, 2026
Threat actors associated with Interlock ransomware exploited a Zimbra XSS flaw CVE-2025-66376 in Cisco's firewall management software.
tactic Ransomware
vulnerability CVE-2026-20131
infrastructure 10.0
organisation Amazon
organisation CVSS
organisation Amazon Integrated Security
organisation MadPot
2026-02-16
Threat actors exploited a Zimbra XSS flaw CVE-2025-66376 to compromise Catalyst SD-WAN controllers.
organisation Catalyst SD-WAN
March 4, 2026
Threat actors exploited a Zimbra XSS flaw CVE-2025-66376 in the Cisco Secure Firewall Management Center web interface to target Ukraine.
organisation Cisco Secure Firewall Management Center
tactic T1592.002 - Software
organisation BleepingComputer
March 4
Russian APT actors exploited a Zimbra XSS flaw CVE-2025-66376 to target Ukraine via the patched vulnerability on March 4.
vulnerability CVE-2026-20131
Mar 18, 2026
Threat actors exploited a recently disclosed Zimbra XSS vulnerability CVE-2025-66376 to target Ukraine.
March 18, 12:55 EDT
Threat actors exploited a Zimbra XSS flaw CVE-2025-66376 to target Ukraine.
Mar 19, 2026
Threat actors exploited a previously unknown Zero-Day Exploit (CVE-2025-66376) in Zimbra to gain unauthorized access and conduct malicious activities against Ukrainian targets.
18, 2026
Ransomware actors exploited a recently disclosed CVE-2025-66376 in Cisco Secure Firewall Management Center Software to target Ukraine.
tactic Ransomware
tactic T1592.002 - Software
attribution Network Security / Ransomware
attribution Amazon Threat Intelligence
attribution Interlock ransomware
attribution Cisco Secure Firewall Management Center
2026-03-19
Russian APT actors exploited a stored XSS vulnerability in Zimbra, CVE-2025-66376.
organisation APT
organisation Zimbra XSS
organisation CVE-2025-66376
organisation Zimbra Collaboration
organisation Seqrite Labs
threat_actor APT28
organisation BlueDelta
threat_actor Winter Vivern
organisation State Hydrology Agency
organisation CVE-2025
organisation a Zimbra XSS
infrastructure Microsoft Office
organisation CVSS
organisation Microsoft Office SharePoint
organisation CSS
organisation HTML
organisation KeV
organisation the Classic UI
organisation Synacor
infrastructure 10.1.13
infrastructure 10.0.18
organisation Operation GhostMail
organisation ZCS
organisation DNS
organisation HTTPS
organisation Kettering Health
organisation the Texas Tech University System
organisation Ransomware
organisation Secure Firewall Management Center
organisation Interlock Ransomware
organisation Root Access
infrastructure Windows
organisation Google
organisation SEO
organisation Amazon
organisation Ivanti
organisation The Red Report 2026
organisation IBM
organisation Amazon Integrated Security
organisation CJ Moses
organisation The Hacker News
organisation Unified Communications
organisation ScreenConnect
organisation Desktop, Documents
organisation Downloads
organisation Chrome, Edge
organisation RDP
infrastructure Linux
organisation HAProxy
organisation IP
organisation ELF
organisation HISTFILE
organisation ConnectWise ScreenConnect
organisation TOR
March 21, 2026
Threat actors exploited a Zimbra XSS flaw CVE-2025-66376 to target Ukrainian organizations.
vulnerability CVE-2025-66376
vulnerability CVE-2026-20963
March 23, 2026
Threat actors exploited a Zimbra XSS flaw CVE-2025-66376 to target Federal Civilian Executive Branch (FCEB) agencies.
vulnerability CVE-2025-66376
vulnerability CVE-2026-20963
attribution Federal Civilian Executive Branch
attribution FCEB
April 1st, 2026
Threat actors exploited a Zimbra XSS flaw CVE-2025-66376 to target Ukrainian organizations.
vulnerability CVE-2025-66376
target_region United States
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
vulnerability CVE-2026-20963
organisation SecurityAffairs
April 1, 2026
Threat actors exploited a Zimbra XSS flaw CVE-2025-66376 to target Ukrainian Federal Civilian Executive Branch agencies.
vulnerability CVE-2025-66376
vulnerability CVE-2026-20963
attribution Federal Civilian Executive Branch
attribution FCEB
April 1st
The agencies were ordered to secure their servers within two weeks of the directive's issuance, as mandated by the Binding Operational Directive 22-01.
attribution the Binding Operational Directive (
Tactical Metrics
Metrics
infrastructure
​10.1.13
Software Version
Metrics
infrastructure
​10.0.18
Software Version
Metrics
infrastructure
​Microsoft Office
Affected Product
Metrics
infrastructure
​10.0
Software Version
Metrics
infrastructure
​8.8
Software Version
Metrics
infrastructure
​Ivanti
Affected Product
Metrics
infrastructure
1,000
Servers
Metrics
infrastructure
900
Servers
Metrics
infrastructure
​Windows
Affected Product
Metrics
infrastructure
​Linux
Affected Product