INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Russian Hackers Exploit Zimbra Zero-Day Against US Ukraine Targets
| 2026-07-23 16:49 CRITICAL HIGHExecutive Summary AI-generated
Russian hackers have been exploiting a recently discovered zero-day vulnerability in the Zimbra Collaboration Suite (ZCS) to compromise networks of Western governments and enterprises, according to intelligence and cybersecurity agencies worldwide. The threat actors behind this campaign are state-backed and have been linked to other advanced persistent threats (APTs), including "Laundry Bear," which has targeted Ukrainian government entities but also US government agencies, defense companies, and scientific organizations. This latest attack marks another example of Russian APTs seeking sensitive information for the Russian Federation. The Laundry Bear attacks demonstrate a growing threat from these actors against US organizations, underscoring the need for increased vigilance and cooperation among nations to counter this emerging cyber threat.
Technical Mitigations AI-generated
* Implement a robust email security solution that includes:
+ Thoroughly scanning and filtering emails for suspicious content
+ Using multi-factor authentication (MFA) to prevent unauthorized access
+ Regularly updating software, plugins, and operating systems to patch known vulnerabilities
+ Employing advanced threat detection and response tools
* Conduct regular email security awareness training for employees to educate them on:
+ How to identify phishing emails and report suspicious activity
+ The importance of using strong passwords and keeping personal devices secure
+ Best practices for avoiding click-through traps, attachments, and links
* Use a web application firewall (WAF) that includes:
+ Intrusion detection and prevention capabilities
+ Advanced threat protection features to detect and block known and unknown threats
+ Support for sandboxing and reverse proxy technologies to isolate sensitive data
* Regularly review and update email security configurations, including:
+ Setting up secure protocols such as TLS 1.2 or higher
+ Configuring IP blocking and rate limiting to prevent abuse
+ Implementing a content filtering system that blocks known phishing sites and malware
These technical mitigations can help protect organizations from the Laundry Bear threat by reducing the attack surface, improving email security awareness, and enhancing overall web application security.
Technical Observables
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation GhostMailOperation GhostMail
APT29APT29APT28APT28Winter VivernWinter Vivern
SofacySofacySednitSednit
CVE-2025-66376CVE-2025-66376
CVE-2020-7796CVE-2020-7796
CVE-2025-68645CVE-2025-68645
CVE-2025-48700CVE-2025-48700
Target & Sectors
BENELUX
BENELUX
NORTH_AMERICA
NORTH_AMERICA
defensedefense
transportationtransportation
energyenergy
aviationaviation
educationeducation
mediamedia
technologytechnology
maritimemaritime
governmentgovernment
Incident Timeline
February 2023
The Russian-sponsored Winter Vivern hacking group used a reflected XSS exploit to breach Zimbra webmail portals.
Click on any entity below to view its context and source!
target_region
Russian Federation
For instance, the Russian-sponsored Winter Vivern hacking group used a reflected XSS exploit
to breach Zimbra webmail portals
in February 2023, stealing emails from NATO-aligned organizations and individuals, including government officials, military personnel, and diplomats.
attribution
NATO
For instance, the Russian-sponsored Winter Vivern hacking group used a reflected XSS exploit
to breach Zimbra webmail portals
in February 2023, stealing emails from NATO-aligned organizations and individuals, including government officials, military personnel, and diplomats.
industry
Government
For instance, the Russian-sponsored Winter Vivern hacking group used a reflected XSS exploit
to breach Zimbra webmail portals
in February 2023, stealing emails from NATO-aligned organizations and individuals, including government officials, military personnel, and diplomats.
threat_actor
Winter Vivern
For instance, the Russian-sponsored Winter Vivern hacking group used a reflected XSS exploit
to breach Zimbra webmail portals
in February 2023, stealing emails from NATO-aligned organizations and individuals, including government officials, military personnel, and diplomats.
at least 2024
Threat actors exploited a critical Zero-Trust Zimbra XSS flaw in the affected organization's email system to gain unauthorized access and compromise user mailboxes.
Click on any entity below to view its context and source!
target_region
Russian Federation
Since at least 2024, the group has focused on intelligence collection against organizations aligned with Russian strategic interests, primarily targeting NATO member states and Ukraine.
target_region
Ukraine
Since at least 2024, the group has focused on intelligence collection against organizations aligned with Russian strategic interests, primarily targeting NATO member states and Ukraine.
attribution
NATO
Since at least 2024, the group has focused on intelligence collection against organizations aligned with Russian strategic interests, primarily targeting NATO member states and Ukraine.
October 2024
Threat actors used a previously abused Zimbra XSS flaw to target and compromise vulnerable mailboxes.
Click on any entity below to view its context and source!
target_region
Russian Federation
In October 2024, U.S. and U.K. cyber agencies have also warned that APT29 (also known as Midnight Blizzard and Cozy Bear) hackers working for Russia's Foreign Intelligence Service (SVR) were
targeting vulnerable Zimbra servers
"at a mass scale" using an exploit that targeted a flaw previously abused
to steal email account credentials
.
threat_actor
APT29
In October 2024, U.S. and U.K. cyber agencies have also warned that APT29 (also known as Midnight Blizzard and Cozy Bear) hackers working for Russia's Foreign Intelligence Service (SVR) were
targeting vulnerable Zimbra servers
"at a mass scale" using an exploit that targeted a flaw previously abused
to steal email account credentials
.
attribution
Foreign Intelligence Service
In October 2024, U.S. and U.K. cyber agencies have also warned that APT29 (also known as Midnight Blizzard and Cozy Bear) hackers working for Russia's Foreign Intelligence Service (SVR) were
targeting vulnerable Zimbra servers
"at a mass scale" using an exploit that targeted a flaw previously abused
to steal email account credentials
.
May 2025
The Laundry Bear hacking group exploited a critical Zero-Trust Access Vulnerability in Zimbra email servers to target governments and police agencies.
Click on any entity below to view its context and source!
source_region
Ukraine
Laundry Bear targeted governments, police, and Ukraine
The Laundry Bear hacking group was first attributed to cyberespionage attacks in May 2025 by the Dutch intelligence agencies.
source_region
Netherlands
Laundry Bear targeted governments, police, and Ukraine
The Laundry Bear hacking group was first attributed to cyberespionage attacks in May 2025 by the Dutch intelligence agencies.
2025/07/23
Threat actors used a "novel exploit" for CVE-2025-66376 to target mailboxes.
Click on any entity below to view its context and source!
tactic
Phishing
Laundry Bear, the authoring agencies said, had previously relied on unsophisticated tactics such as
password spraying
and conventional phishing attacks until last year, when actors began using a "novel exploit" for CVE-2025-66376 that no longer required targeted victims to click on a link or open a malicious email attachment.
vulnerability
CVE-2025-66376
Laundry Bear, the authoring agencies said, had previously relied on unsophisticated tactics such as
password spraying
and conventional phishing attacks until last year, when actors began using a "novel exploit" for CVE-2025-66376 that no longer required targeted victims to click on a link or open a malicious email attachment.
July 2025
Threat actors used a Zero-Trust Security Control in Zimbra to target mailboxes.
Click on any entity below to view its context and source!
industry
Government
In a
joint advisory
Thursday, the US government and several allied nations warned that an advanced persistent threat (APT) dubbed "Laundry Bear" has been targeting ZCS customers since July 2025.
target_region
United States
In a
joint advisory
Thursday, the US government and several allied nations warned that an advanced persistent threat (APT) dubbed "Laundry Bear" has been targeting ZCS customers since July 2025.
attribution
ZCS
In a
joint advisory
Thursday, the US government and several allied nations warned that an advanced persistent threat (APT) dubbed "Laundry Bear" has been targeting ZCS customers since July 2025.
attribution
APT
In a
joint advisory
Thursday, the US government and several allied nations warned that an advanced persistent threat (APT) dubbed "Laundry Bear" has been targeting ZCS customers since July 2025.
November 2025
Laundry Bear exploited a zero-day XSS flaw in Zimbra's version 10.1.13 to target organizations running unpatched servers until November 2025.
Click on any entity below to view its context and source!
attribution
Laundry Bear
According to CISA, Laundry Bear exploited the flaw as a zero-day before Zimbra patched it in November 2025 and continues to target organizations running unpatched servers.
attribution
CISA
According to CISA, Laundry Bear exploited the flaw as a zero-day before Zimbra patched it in November 2025 and continues to target organizations running unpatched servers.
vulnerability
CVE-2025-66376
Zimbra Zero-Day Activity
Zimbra patched CVE-2025-66376 in November 2025 with the release of version 10.1.13, though the company did not disclose the flaw until weeks later.
infrastructure
10.1.13
Zimbra Zero-Day Activity
Zimbra patched CVE-2025-66376 in November 2025 with the release of version 10.1.13, though the company did not disclose the flaw until weeks later.
organisation
CVE-2025
Zimbra Zero-Day Activity
Zimbra patched CVE-2025-66376 in November 2025 with the release of version 10.1.13, though the company did not disclose the flaw until weeks later.
January 22
Threat actors exploited a critical Zero-Trust Access Insecurity Boosting (Zimbra XSS Flaw) in the compromised student email to gain unauthorized access.
Click on any entity below to view its context and source!
industry
Maritime
A national maritime agency was targeted on January 22 using a compromised student email.
March 17
Russian threat actors exploited CVE-2025-66376 in the compromise of a Ukrainian government agency on March 17.
Click on any entity below to view its context and source!
source_region
Russian Federation
In a March 17
blog post
, cybersecurity firm Seqrite reported that Russian threat actors had exploited CVE-2025-66376 in the compromise of a Ukrainian government agency.
target_region
Ukraine
In a March 17
blog post
, cybersecurity firm Seqrite reported that Russian threat actors had exploited CVE-2025-66376 in the compromise of a Ukrainian government agency.
industry
Government
In a March 17
blog post
, cybersecurity firm Seqrite reported that Russian threat actors had exploited CVE-2025-66376 in the compromise of a Ukrainian government agency.
vulnerability
CVE-2025-66376
In a March 17
blog post
, cybersecurity firm Seqrite reported that Russian threat actors had exploited CVE-2025-66376 in the compromise of a Ukrainian government agency.
attribution
Seqrite
In a March 17
blog post
, cybersecurity firm Seqrite reported that Russian threat actors had exploited CVE-2025-66376 in the compromise of a Ukrainian government agency.
March 18
Threat actors exploited a Critical Zimbra XSS Flaw to target mailboxes in the United States.
Click on any entity below to view its context and source!
source_region
United States
The following day, the US Cybersecurity and Infrastructure Security Agency (CISA) added the high-severity vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on March 18.
attribution
Known Exploited
The following day, the US Cybersecurity and Infrastructure Security Agency (CISA) added the high-severity vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on March 18.
tactic
T1588.006 - Vulnerabilities
The following day, the US Cybersecurity and Infrastructure Security Agency (CISA) added the high-severity vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on March 18.
attribution
KEV
The following day, the US Cybersecurity and Infrastructure Security Agency (CISA) added the high-severity vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on March 18.
2026/07/23
Russian hackers exploited a previously unknown Zimbra XSS vulnerability (CVE-2025-66376) to target Ukrainian government entities.
Click on any entity below to view its context and source!
organisation
CVE-2025-66376
In March, Russia-linked APT group, likely
APT28
(aka UAC-0001, aka
Fancy Bear
,
Pawn Storm
,
Sofacy Group
,
Sednit
, BlueDelta, and
STRONTIUM
),
exploited
the vulnerability
CVE-2025-66376
in attacks against entities in Ukraine.
Laundry Bear actors used a
zero-day vulnerability in ZCS
, tracked as CVE-2025-66376, in a phishing campaign that featured what experts describe as a "half-click exploit" to breach Zimbra webmail servers.
threat_actor
APT28
In March, Russia-linked APT group, likely
APT28
(aka UAC-0001, aka
Fancy Bear
,
Pawn Storm
,
Sofacy Group
,
Sednit
, BlueDelta, and
STRONTIUM
),
exploited
the vulnerability
CVE-2025-66376
in attacks against entities in Ukraine.
More recently, in March, the Cybersecurity and Infrastructure Security Agency (CISA)
ordered federal agencies
to patch another Zimbra XSS flaw (CVE-2025-66376) exploited by hackers linked to the APT28 group (linked to Russia's military intelligence service) in
attacks targeting Ukrainian government entities
.
At the time, Seqrite attributed the activity, which it called "Operation GhostMail," to APT28, also known as
Fancy Bear
.
organisation
APT
In March, Russia-linked APT group, likely
APT28
(aka UAC-0001, aka
Fancy Bear
,
Pawn Storm
,
Sofacy Group
,
Sednit
, BlueDelta, and
STRONTIUM
),
exploited
the vulnerability
CVE-2025-66376
in attacks against entities in Ukraine.
Additionally, the researchers warned that it's possible the APT group may be
using large language models
to "develop a bypass for Zimbra's patch to continue targeting Zimbra servers."
organisation
BlueDelta
In March, Russia-linked APT group, likely
APT28
(aka UAC-0001, aka
Fancy Bear
,
Pawn Storm
,
Sofacy Group
,
Sednit
, BlueDelta, and
STRONTIUM
),
exploited
the vulnerability
CVE-2025-66376
in attacks against entities in Ukraine.
organisation
BleepingComputer
Earlier this year, BleepingComputer reported on a separate
Laundry Bear campaign targeting Ukraine's military
using charity-themed phishing emails to deliver malware disguised as donation requests.
organisation
HTML
The flaw allows JavaScript embedded in specially crafted HTML emails to execute automatically when a victim views the message, enabling attackers to steal account data without requiring the user to click a link or visit a phishing site.
The message hid malicious JavaScript in the HTML body, exploiting a Zimbra XSS flaw (CVE-2025-66376).
The
initial release notes
for v10.1.13 merely described the flaw as "a stored
XSS vulnerability
in the Classic UI where attackers could abuse CSS @import directives in email HTML," with no CVE at the time.
organisation
Laundry Bear
In addition to exploiting the Zimbra flaw, Laundry Bear also utilizes adversary-in-the-middle (AiTM) phishing kits designed to impersonate legitimate Zimbra login portals, stealing credentials and session cookies, allowing the attackers to gain access to targets' email accounts.
Laundry Bear actors used a
zero-day vulnerability in ZCS
, tracked as CVE-2025-66376, in a phishing campaign that featured what experts describe as a "half-click exploit" to breach Zimbra webmail servers.
organisation
AiTM
In addition to exploiting the Zimbra flaw, Laundry Bear also utilizes adversary-in-the-middle (AiTM) phishing kits designed to impersonate legitimate Zimbra login portals, stealing credentials and session cookies, allowing the attackers to gain access to targets' email accounts.
organisation
ZCS
Laundry Bear actors used a
zero-day vulnerability in ZCS
, tracked as CVE-2025-66376, in a phishing campaign that featured what experts describe as a "half-click exploit" to breach Zimbra webmail servers.
In April,
nonprofit security organization Shadowserver warned
that over 10,500 Zimbra Collaboration Suite (ZCS) instances exposed online were still vulnerable to ongoing attacks exploiting another cross-site scripting (XSS) security flaw (tracked as CVE-2025-48700).
organisation
State Hydrology Agency
A phishing email targeted Ukraine’s State Hydrology Agency, part of critical infrastructure, using a compromised student account to appear legitimate.
organisation
a Zimbra XSS
The message hid malicious JavaScript in the HTML body, exploiting a Zimbra XSS flaw (CVE-2025-66376).
infrastructure
1.13
The
initial release notes
for v10.1.13 merely described the flaw as "a stored
XSS vulnerability
in the Classic UI where attackers could abuse CSS @import directives in email HTML," with no CVE at the time.
organisation
CSS
The
initial release notes
for v10.1.13 merely described the flaw as "a stored
XSS vulnerability
in the Classic UI where attackers could abuse CSS @import directives in email HTML," with no CVE at the time.
organisation
Zimbra Collaboration Suite's
The attackers exploit the Zimbra
CVE-2025-66376
flaw, a cross-site scripting (XSS) vulnerability affecting Zimbra Collaboration Suite's Classic UI.
organisation
Synacor
Dark Reading contacted Zimbra and parent company Synacor for comment on the apparent delayed disclosure for CVE-2025-66376, but neither company responded at press time.
organisation
IMAP
The attackers also create and send back a new Zimbra application passcode, which is used by legacy email clients like IMAP or ActiveSync that do not support the TOTP authentication flows.
organisation
ActiveSync
The attackers also create and send back a new Zimbra application passcode, which is used by legacy email clients like IMAP or ActiveSync that do not support the TOTP authentication flows.
organisation
MFA
Using a passcode allows the attackers to retain access to the email account while bypassing MFA.
organisation
DNS
Smaller data is encoded and transmitted in DNS A-record queries, while larger payloads, including mailbox data, are uploaded over HTTPS as compressed archives to the attacker-controlled servers.
Then they exfiltrated stolen data via DNS and HTTPS.
organisation
HTTPS
Smaller data is encoded and transmitted in DNS A-record queries, while larger payloads, including mailbox data, are uploaded over HTTPS as compressed archives to the attacker-controlled servers.
Then they exfiltrated stolen data via DNS and HTTPS.
organisation
IP
Investigate systems for connections to the identified domains and IP addresses.
organisation
ZimbraWeb
Revoke any unauthorized application passcodes, especially those with the 'ZimbraWeb'.
organisation
Microsoft
Microsoft tracks the same group under the name Void Blizzard.
organisation
EDR
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
organisation
Frozen-Food Chain
Laundry Bear's 'Half-Click'
Related:
Ransomware Attack Puts a Chill on Japanese Frozen-Food Chain
Laundry Bear's 'Half-Click' Zimbra Exploit
organisation
CVE-2025-48700
In April,
nonprofit security organization Shadowserver warned
that over 10,500 Zimbra Collaboration Suite (ZCS) instances exposed online were still vulnerable to ongoing attacks exploiting another cross-site scripting (XSS) security flaw (tracked as CVE-2025-48700).
organisation
Shadowserver
In April,
nonprofit security organization Shadowserver warned
that over 10,500 Zimbra Collaboration Suite (ZCS) instances exposed online were still vulnerable to ongoing attacks exploiting another cross-site scripting (XSS) security flaw (tracked as CVE-2025-48700).
organisation
Operation GhostMail
Seqrite Labs tracked this campaign as Operation GhostMail.
organisation
Seqrite
They also noted that the threat actors used the exploit for "at least five months during 2025" and appeared to cease operations in February following Seqrite's detection.
infrastructure
10.1.19
Zimbra has released version 10.1.19 to fix a critical stored XSS vulnerability in its Classic Web Client, which is widely used to access Zimbra Collaboration.
The company released Zimbra 10.1.19 this Tuesday to patch this stored cross-site scripting (XSS) security flaw, which has yet to receive a CVE ID for easy tracking.
organisation
the Classic Web Client
“The update fixes a security issue in the Classic Web Client where a specially crafted email could run malicious code when the email is opened.
organisation
ZCS v10.1.19
If exploited, it could allow access to mailbox information, session data, or account settings.” reads the
advisory
“We strongly recommend all customers to upgrade to ZCS v10.1.19 to ensure they have received the latest security patches, bug fixes, and enhancements.”
Google’s Threat Analysis Group discovered the vulnerability.
"Any customer using the Classic Web Client should upgrade to ZCS v10.1.19 as soon as possible, as this issue only impacts the users of Classic Web Client,"
Zimbra warned
.
organisation
Google’s Threat Analysis Group
If exploited, it could allow access to mailbox information, session data, or account settings.” reads the
advisory
“We strongly recommend all customers to upgrade to ZCS v10.1.19 to ensure they have received the latest security patches, bug fixes, and enhancements.”
Google’s Threat Analysis Group discovered the vulnerability.
organisation
SecurityAffairs
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, XSS)
organisation
the Classic UI
Also known as the Classic UI, this Ajax-based webmail interface is faster than Zimbra's modern web client, which requires more resources when loading large email folders.
organisation
Ajax
Also known as the Classic UI, this Ajax-based webmail interface is faster than Zimbra's modern web client, which requires more resources when loading large email folders.
organisation
Google
"
While Zimbra has not yet tagged this vulnerability as exploited in the wild, the flaw was reported by Google's Threat Analysis Group, which frequently flags zero-day exploits deployed by state-backed hacking groups in cyberattacks targeting high-risk individuals, including opposition politicians, dissidents, and journalists.
organisation
Threat Analysis Group
"
While Zimbra has not yet tagged this vulnerability as exploited in the wild, the flaw was reported by Google's Threat Analysis Group, which frequently flags zero-day exploits deployed by state-backed hacking groups in cyberattacks targeting high-risk individuals, including opposition politicians, dissidents, and journalists.
the beginning of 2026
Threat actors exploited a Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability to target mailboxes.
Click on any entity below to view its context and source!
vulnerability
CVE-2025-66376
Since the beginning of 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added [
1
,
2
,
3
] the following vulnerabilities to its
Known Exploited Vulnerabilities (KEV) catalog
:
CVE-2025-68645
(CVSS score of 8.8) Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability
CVE-2020-7796
(CVSS score of 9.8) Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability
CVE-2025-66376
(CVSS score of 7.2) Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability.
attribution
Known Exploited
Since the beginning of 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added [
1
,
2
,
3
] the following vulnerabilities to its
Known Exploited Vulnerabilities (KEV) catalog
:
CVE-2025-68645
(CVSS score of 8.8) Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability
CVE-2020-7796
(CVSS score of 9.8) Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability
CVE-2025-66376
(CVSS score of 7.2) Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability.
tactic
T1588.006 - Vulnerabilities
Since the beginning of 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added [
1
,
2
,
3
] the following vulnerabilities to its
Known Exploited Vulnerabilities (KEV) catalog
:
CVE-2025-68645
(CVSS score of 8.8) Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability
CVE-2020-7796
(CVSS score of 9.8) Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability
CVE-2025-66376
(CVSS score of 7.2) Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability.
attribution
KEV
Since the beginning of 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added [
1
,
2
,
3
] the following vulnerabilities to its
Known Exploited Vulnerabilities (KEV) catalog
:
CVE-2025-68645
(CVSS score of 8.8) Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability
CVE-2020-7796
(CVSS score of 9.8) Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability
CVE-2025-66376
(CVSS score of 7.2) Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability.
vulnerability
CVE-2025-68645
Since the beginning of 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added [
1
,
2
,
3
] the following vulnerabilities to its
Known Exploited Vulnerabilities (KEV) catalog
:
CVE-2025-68645
(CVSS score of 8.8) Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability
CVE-2020-7796
(CVSS score of 9.8) Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability
CVE-2025-66376
(CVSS score of 7.2) Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability.
vulnerability
CVE-2020-7796
Since the beginning of 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added [
1
,
2
,
3
] the following vulnerabilities to its
Known Exploited Vulnerabilities (KEV) catalog
:
CVE-2025-68645
(CVSS score of 8.8) Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability
CVE-2020-7796
(CVSS score of 9.8) Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability
CVE-2025-66376
(CVSS score of 7.2) Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability.
vulnerability
CVSS score of 8.8
Since the beginning of 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added [
1
,
2
,
3
] the following vulnerabilities to its
Known Exploited Vulnerabilities (KEV) catalog
:
CVE-2025-68645
(CVSS score of 8.8) Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability
CVE-2020-7796
(CVSS score of 9.8) Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability
CVE-2025-66376
(CVSS score of 7.2) Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability.
vulnerability
CVSS score of 9.8
Since the beginning of 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added [
1
,
2
,
3
] the following vulnerabilities to its
Known Exploited Vulnerabilities (KEV) catalog
:
CVE-2025-68645
(CVSS score of 8.8) Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability
CVE-2020-7796
(CVSS score of 9.8) Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability
CVE-2025-66376
(CVSS score of 7.2) Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability.
vulnerability
CVSS score of 7.2
Since the beginning of 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added [
1
,
2
,
3
] the following vulnerabilities to its
Known Exploited Vulnerabilities (KEV) catalog
:
CVE-2025-68645
(CVSS score of 8.8) Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability
CVE-2020-7796
(CVSS score of 9.8) Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability
CVE-2025-66376
(CVSS score of 7.2) Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability.
attribution
CVSS
Since the beginning of 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added [
1
,
2
,
3
] the following vulnerabilities to its
Known Exploited Vulnerabilities (KEV) catalog
:
CVE-2025-68645
(CVSS score of 8.8) Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability
CVE-2020-7796
(CVSS score of 9.8) Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability
CVE-2025-66376
(CVSS score of 7.2) Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability.
attribution
PHP Remote File Inclusion Vulnerability
Since the beginning of 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added [
1
,
2
,
3
] the following vulnerabilities to its
Known Exploited Vulnerabilities (KEV) catalog
:
CVE-2025-68645
(CVSS score of 8.8) Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability
CVE-2020-7796
(CVSS score of 9.8) Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability
CVE-2025-66376
(CVSS score of 7.2) Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability.
tactic
T1584.004 - Server
Since the beginning of 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added [
1
,
2
,
3
] the following vulnerabilities to its
Known Exploited Vulnerabilities (KEV) catalog
:
CVE-2025-68645
(CVSS score of 8.8) Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability
CVE-2020-7796
(CVSS score of 9.8) Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability
CVE-2025-66376
(CVSS score of 7.2) Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability.
general_metric
1 CISA
Since the beginning of 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added [
1
,
2
,
3
] the following vulnerabilities to its
Known Exploited Vulnerabilities (KEV) catalog
:
CVE-2025-68645
(CVSS score of 8.8) Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability
CVE-2020-7796
(CVSS score of 9.8) Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability
CVE-2025-66376
(CVSS score of 7.2) Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability.
general_metric
2 CISA
Since the beginning of 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added [
1
,
2
,
3
] the following vulnerabilities to its
Known Exploited Vulnerabilities (KEV) catalog
:
CVE-2025-68645
(CVSS score of 8.8) Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability
CVE-2020-7796
(CVSS score of 9.8) Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability
CVE-2025-66376
(CVSS score of 7.2) Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability.
Tactical Metrics
Metrics
infrastructure
10.1.13
Software Version
Click for context!
Zimbra Zero-Day Activity
Zimbra patched CVE-2025-66376 in November 2025 with the release of version 10.1.13, though the company did not disclose the flaw until weeks later.
Metrics
infrastructure
1.13
Software Version
The
initial release notes
for v10.1.13 merely described the flaw as "a stored
XSS vulnerability
in the Classic UI where attackers could abuse CSS @import directives in email HTML," with no CVE at the time.
Metrics
infrastructure
10.1.19
Software Version
Zimbra has released version 10.1.19 to fix a critical stored XSS vulnerability in its Classic Web Client, which is widely used to access Zimbra Collaboration.
The company released Zimbra 10.1.19 this Tuesday to patch this stored cross-site scripting (XSS) security flaw, which has yet to receive a CVE ID for easy tracking.
Intelligence Sources
Security Affairs
2026-07-10
BleepingComputer
2026-07-10
Zimbra urges customers to patch critical web client XSS flaw
BleepingComputer
Dark Reading
2026-07-23
BleepingComputer
2026-07-23
Russian hackers exploit Zimbra zero-click flaw for email theft
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Reset / Delete
Incident Version History
CURRENT VERSION
Last Updated: 2026-07-24T06:32
Comprehensive Tactical Telemetry
Highly Correlated Entities
37x
organisation
Identified Entity
BleepingComputer
entity
24x
attribution
Attributing Entity
Laundry Bear
authority
17x
timeline
Temporal Reference
May 2025
date
9x
industry
Targeted Sector
Defense
sector
7x
target region
Target Country
Netherlands
country
5x
tactic
Cyber Operation Type
Phishing
tactic
4x
source region
Origin Country
Russian Federation
country
4x
vulnerability
Exploited CVE
CVE-2025-66376
cve
3x
tactic
MITRE ATT&CK Technique
T1059.007 - JavaScript
technique
3x
infrastructure
Software Version
10.1.13
version
3x
threat actor
APT Group
APT28
actor
3x
vulnerability
CVSS Score
9
score
2x
general metric
%
54
%
2x
malware
Malware Payload
Sofacy
tool
2x
general metric
Cisa
1
cisa
Contextual Telemetry
Context Block
5 METRICS
campaign
Campaign
Operation GhostMail
operation
general metric
Cvss Score
7
cvss score
general metric
Different Countries
15
different countries
general metric
Least July
2,025
least july
general metric
Collaboration Suite
10,500
collaboration suite
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.