CVE-2025-66376

Published Jan 5, 2026

Last updated 5 months ago

Exploit knownCVSS high 7.2
web application
Zero-day
Server
OT

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-66376 is a stored Cross-Site Scripting (XSS) vulnerability found in Zimbra Collaboration (ZCS) affecting its Classic UI component. This flaw enables attackers to inject malicious scripts into the system through specially crafted HTML email messages. The vulnerability specifically exploits the way the Classic UI processes Cascading Style Sheets (CSS) `@import` directives embedded within these emails. When a user views a malicious email in the vulnerable Classic UI, the injected script can execute within the context of their browser session. This vulnerability is categorized under CWE-79, which refers to improper neutralization of input during web page generation, stemming from insufficient sanitization of CSS content in HTML email messages. Affected versions include Zimbra Collaboration (ZCS) 10 prior to version 10.0.18 and ZCS 10.1 prior to version 10.1.13.

Description
Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.
Source
cve@mitre.org
NVD status
Analyzed
Products
zimbra_collaboration_suite

Risk scores

CVSS 3.1

Type
Primary
Base score
6.1
Impact score
2.7
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Severity
MEDIUM

Known exploits

Data from CISA

Vulnerability name
Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability
Exploit added on
Mar 18, 2026
Exploit action due
Apr 1, 2026
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weaknesses

cve@mitre.org
CWE-79

Social media

Hype score
Not currently trending
  1. Zero-click phishing is here. Russian state actors (LAUNDRY BEAR) deployed CVE-2025-66376 against Zimbra. No user click needed. Just viewing an email compromises your system. NCSC + 16 nations just issued coordinated alert. Patch now. Read: https://t.co/08WT9fgg3S https://t.co

    @DarkInvaderIO

    28 Jul 2026

    50 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Russian 🇷🇺 state-sponsored group Laundry Bear exploited Zimbra CVE-2025-66376 as a zero-day since July 2025, targeting Western government, defense, and critical infrastructure via zero-click email to steal credentials and 2FA tokens. Key findings: - CVE-2025-66376 is a CS

    @DFIR_Radar

    28 Jul 2026

    248 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  3. 📧 Russian state-backed Laundry Bear exploited CVE-2025-66376 against Zimbra webmail. Simply viewing a malicious email could expose passwords, 2FA tokens, directories and up to 90 days of email. #CyberEspionage #Zimbra #CVE Source: CISA and Unit 42.

    @XQOPTRX

    27 Jul 2026

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. A click-free Zimbra webmail flaw (CVE-2025-66376) let a Russian state-linked group read government and defence mailboxes for a year before attribution. NCSC, 15 partner agencies, and Unit 42 confirmed it this week. Patched since November, unpatched instances are still being hit.

    @CloudCrestSec

    27 Jul 2026

    28 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  5. 『TA488 sent messages exploiting CVE-2025-66376 from both adversary-controlled Proton Mail accounts and previously compromised addresses, to target entities in the government and education sectors』 TA488 Targets Zimbra Mailservers with Half-Click Exploits https://t.co/aud8Fpw5

    @autumn_good_35

    27 Jul 2026

    394 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  6. Russian group LAUNDRY BEAR used zero-day CVE-2025-66376 in Zimbra to steal emails via stored XSS without user interaction.

    @WorldCyberNewsX

    27 Jul 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. #threatreport #MediumCompleteness CVE-2025-66376: Russian APT Exploits Zimbra Zero-Day | 25-07-2026 Source: https://t.co/EAzsvGrObC Key details below ↓ 🧑‍💻Actors/Campaigns: Void_blizzard 💀Threats: Flowerbed_tool, 🎯Victims: Government, Commercial organizations,

    @rst_cloud

    27 Jul 2026

    218 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. ACSC: Russian state actors exploit a Zimbra zero-click flaw (CVE-2025-66376). Patch and hunt. https://t.co/pe1KfchdnE https://t.co/esBY1X6EVj

    @CyberPulse_aus

    27 Jul 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. Sixteen agencies warned that opening a Zimbra message can empty the mailbox. CVE-2025-66376 is view-only: Classic webmail displaying the message is enough. Payload plants a ZimbraWeb app passcode for IMAP past MFA. #EmailSecurity #CISA

    @_alexeysorokin

    26 Jul 2026

    24 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  10. Zero-Click Phishing: Russische Gruppe infiziert beim E-Mail-Ansehen. CVE-2025-66376 in Zimbra seit Juli 2025 aktiv. #Phishing #CVE https://t.co/k5Xkegavfs

    @wall_your_x

    26 Jul 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. Russian state-sponsored actors tracked as Laundry Bear (also Void Blizzard, TA488, CL-STA-1114) have been exploiting a Zimbra Collaboration Suite zero-day since July 2025. The vulnerability, CVE-2025-66376, is a stored cross-site scripting flaw in the Classic UI. Malicious

    @JAVI_MEI

    26 Jul 2026

    244 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. Russian state-sponsored actors tracked as Laundry Bear (also Void Blizzard, TA488, CL-STA-1114) have been exploiting a Zimbra Collaboration Suite zero-day since July 2025. The vulnerability, CVE-2025-66376, is a stored cross-site scripting flaw in the Classic UI. Malicious

    @JAVI_MEI

    26 Jul 2026

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. 🚨 Laundry Bear Targets US and Ukraine Through Zimbra https://t.co/6avNjCXIeB Russian state-backed group Laundry Bear is exploiting the Zimbra zero-day CVE-2025-66376 to target US and Ukrainian government, defense, and scientific organizations. The attack doesn't require

    @Huntio

    25 Jul 2026

    991 Impressions

    1 Retweet

    15 Likes

    5 Bookmarks

    1 Reply

    0 Quotes

  14. Zimbra-Classic-Web-Client: Zimbra-Zero-Day CVE-2025-66376 ermöglicht Mail-Diebstahl und 2FA-Scratch-Codes: https://t.co/oyN88Xq8bc - #hacker #news #technology #technologie #it #informationstechnologie #hacking #computer #nerds #itsicherheit #itsecurity #itnews #cybercrime #cybe

    @mitchcasspari

    25 Jul 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. Zimbra otra vez en la mira. CISA, la NSA y el FBI alertaron por CVE-2025-66376, y no es una alerta teórica: LAUNDRY BEAR la estaría usando para robar correos, 2FA y contraseñas con un email. Un mail. Y te vacían la caja fuerte. Ahí está el problema. https://t.co/IjpSQHNdN

    @FedeJoelH

    25 Jul 2026

    24 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. CVE-2025-66376 (CVSS 6.1): Russian 🇷🇺 APT LAUNDRY BEAR exploited a Zimbra stored-XSS zero-day for mailbox theft across Western government and commercial targets, active since at least July 2025 and listed in CISA KEV. - CVE-2025-66376 is a stored XSS (CWE-79) in Zimbra Cla

    @DFIR_Radar

    25 Jul 2026

    158 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  17. Russia-linked Laundry Bear is using zero-click phishing against Zimbra users in the West, exploiting CVE-2025-66376 in a likely espionage campaign affecting government and commercial targets. #Zimbra #Russia #Ukraine https://t.co/Wyu9voA8sE

    @TweetThreatNews

    25 Jul 2026

    187 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. 🚨 Zero-Click Espionage Alert The Russian-linked Laundry Bear APT exploited CVE-2025-66376 in Zimbra, letting attackers steal emails, session tokens & bypass MFA simply by viewing a malicious email. 🔗 https://t.co/bAhDIVaJkG #CyberSecurity #ThreatIntel #Zimbra #CVE #I

    @Xploitzone_01

    25 Jul 2026

    66 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. US agencies warn Laundry Bear exploited CVE-2025-66376 to silently steal emails from unpatched Zimbra servers via zero-click JavaScript in malicious emails, with guidance to patch, monitor, and enforce MFA. https://t.co/mWpW8towLh

    @Cyber_O51NT

    25 Jul 2026

    3159 Impressions

    3 Retweets

    14 Likes

    6 Bookmarks

    1 Reply

    2 Quotes

  20. Russian 🇷🇺 APT Laundry Bear exploited Zimbra zero-day CVE-2025-66376 via zero-click phishing, stealing 90 days of email, passwords, and 2FA tokens from US 🇺🇸 and NATO targets. Patch Zimbra immediately or switch mail clients. #DFIR_Radar https://t.co/GcfYQ01LbQ

    @DFIR_Radar

    25 Jul 2026

    176 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  21. A stored XSS flaw in webmail = a VIP pass to your inbox. ✉️💥 CVE-2025-66376 in Zimbra Collaboration Suite was exploited as a zero-day by Russian APT LAUNDRY BEAR (aka Void Blizzard). It allows attackers to steal mailboxes and hijack active sessions. We broke down the roo

    @socradar

    24 Jul 2026

    449 Impressions

    0 Retweets

    2 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  22. Attackers are finding more ways in. 🚨 🤖 AI/LLM tool exposures jumped 60% in nine months, expanding attack surfaces. 🎯 TA488 exploited Zimbra CVE-2025-66376 in attacks on government mail servers. Validate internet-facing assets and patch critical vulnerabilities. https:

    @eSecurityPlanet

    24 Jul 2026

    94 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  23. Laundry Bear APT exploited Zimbra zero-day CVE-2025-66376 to steal session cookies through malicious 'half-click' emails requiring only preview to execute. Attackers then moved laterally within networks to access sensitive systems. Runtime segmentation helps limit blast radius of

    @aviatrixtrc

    24 Jul 2026

    58 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. TRC analysis shows Russian state-sponsored group Laundry Bear exploited zero-day CVE-2025-66376 in Zimbra Collaboration Suite via malicious HTML emails. Attackers executed JavaScript to steal credentials, then moved laterally across email accounts to exfiltrate sensitive data.

    @aviatrixtrc

    24 Jul 2026

    65 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  25. Russian state-hacker group LAUNDRY BEAR (a.k.a. TA488) has stolen 90 days worth of emails from Zimbra Collaboration Suite (ZCS) organizations. Laundry Bear utilized CVE-2025-66376, which is a cross-site scripting flaw. CVE-2025-66376 is a "half-click exploit", where the victim

    @Leila97726926

    24 Jul 2026

    34 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. 1/3 Just opening an email was enough. A Russian espionage crew read government mailboxes for months through a Zimbra zero-day (CVE-2025-66376), stealing 90 days of mail, saved passwords and 2FA codes. Are you patched? #ZeroDay #CyberSecurity #InfoSec #SplatoonRaiders https://t.co

    @CyberTLDR

    24 Jul 2026

    48 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  27. Zimbra patching is only step one. CVE-2025-66376 was exploited before its November 2025 fix, so defenders should verify exposed versions, review webmail and account-change logs, and investigate mailbox access during the vulnerable window. https://t.co/eph1DBpgrq

    @TheClawdLab

    24 Jul 2026

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  28. 🛡️ DEFENDER SIGNAL Russian state actors still exploit Zimbra CVE-2025-66376. Viewing a crafted email can expose credentials, 2FA material & mail history. 🔐 Patch, assess compromise & revoke auth artifacts. 📡 https://t.co/Qr4hAlehfQ

    @supernovanomad

    24 Jul 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  29. 🔒 CYBERSECURITY, PRIVACY & OPEN SOURCE ROUNDUP — July 24, 2026 1️⃣ ZIMBRA ZERO-DAY: RUSSIAN LAUNDRY BEAR STEALS 90 DAYS OF EMAIL Russian state hackers known as LAUNDRY BEAR are actively exploiting CVE-2025-66376, a zero-click vulnerability in Zimbra Collaboration S

    @TraffAlex

    24 Jul 2026

    217 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  30. Zimbra Zero-Day: LAUNDRY BEAR Steals 90 Days of Email Russian state hackers exploit CVE-2025-66376, a zero-click Zimbra flaw, to siphon 90 days of mail, contacts and 2FA tokens. Patch now. https://t.co/r6shKfO9bL #cybersecurity #infosec #zeroday

    @pillitterip

    24 Jul 2026

    63 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  31. Russian-warned APT Laundry Bear is actively exploiting CVE-2025-66376, a zero-click XSS flaw in Zimbra Collaboration Suite, using custom tooling to silently steal mailboxes at scale. Key findings: - CVE-2025-66376 is an XSS vulnerability exploited as a zero-day before patching

    @DFIR_Radar

    24 Jul 2026

    210 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  32. Proofpoint uncovered that Russia-aligned threat actor TA488 (Void Blizzard, Laundry Bear) was exploiting a previously unknown vulnerability against Zimbra mailservers for at least five months during 2025, until the issue was patched with CVE-2025-66376. https://t.co/Y62oigZOym ht

    @virusbtn

    24 Jul 2026

    1966 Impressions

    5 Retweets

    14 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  33. 🚨 Russian hacking group Laundry Bear (Void Blizzard) is exploiting a zero-click Zimbra flaw (CVE-2025-66376) to silently steal emails, passwords & 2FA tokens — no clicks required. Zimbra patched it in Nov 2025, but unpatched servers are still being hit. Update ASAP.

    @techepages

    24 Jul 2026

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  34. LAUNDRY BEAR, a Russian 🇷🇺 state-linked APT, weaponized CVE-2025-66376 as a zero-day against Zimbra Collaboration Suite, stealing 90 days of email, credentials, 2FA tokens, and Global Address Lists from Western government and defense targets since July 2025. Key findings:

    @DFIR_Radar

    24 Jul 2026

    188 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  35. Russian 🇷🇺 Laundry Bear (Void Blizzard/TA488) exploited CVE-2025-66376, a stored XSS zero-day in Zimbra webmail, to deploy the Ulej tool and harvest credentials, session tokens, 2FA backup codes, and 90 days of mailbox content. #DFIR_Radar https://t.co/10FtrOKVfl

    @DFIR_Radar

    24 Jul 2026

    184 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  36. Proofpoint and US authorities reported TA488 (Void Blizzard) exploited a Zimbra CVE-2025-66376 half-click flaw to exfiltrate emails from Ukrainian and US government and defense targets, establishing persistent access via ZimbraWeb credentials. https://t.co/qdWM5H5CVG

    @Cyber_O51NT

    24 Jul 2026

    703 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  37. Russian 🇷🇺 Laundry Bear (Void Blizzard) exploited Zimbra zero-day CVE-2025-66376 (CVSS 6.1) since July 2025, stealing 90 days of email, passwords, and 2FA tokens via a view-only JavaScript payload. #DFIR_Radar https://t.co/8FZfWeP0uU

    @DFIR_Radar

    24 Jul 2026

    142 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  38. Exploited vulnerability in Zimbra's Classic Webmail UI compromises email accounts. Extensive info, incl. fix info, now at SecAlerts: CVE-2025-66376, CVSS 7.2: https://t.co/48FkOVrlHV #ciso #cio #cto #vulnerabilities #cybersecurity #msp #mssp #secalerts #CVE202566376 #Zimbra ht

    @SecAlertsCo

    24 Jul 2026

    177 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  39. Russian state-backed Laundry Bear is exploiting Zimbra CVE-2025-66376 with malicious HTML emails that auto-run JavaScript, stealing mailboxes and bypassing MFA across government, defense, and other sectors. #Russia #Zimbra #LaundryBear https://t.co/9XJ7eApRRX

    @TweetThreatNews

    24 Jul 2026

    178 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  40. Russian state-sponsored group Laundry Bear exploited CVE-2025-66376 to execute zero-click email attacks against defense and government targets. Attackers created persistent application passcodes and moved laterally through compromised email infrastructure. Runtime segmentation

    @aviatrixtrc

    24 Jul 2026

    34 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  41. TRC analysis shows Russian state group LAUNDRY BEAR exploited CVE-2025-66376 with 'view-based' attacks requiring zero user interaction. Attackers moved laterally through Zimbra environments to exfiltrate 90 days of emails plus 2FA recovery codes. Runtime segmentation helps

    @aviatrixtrc

    24 Jul 2026

    28 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  42. ロシア政府支援のスパイ集団が、当時未修正だったZimbraの脆弱性CVE-2025-66376を悪用し、利用者が細工されたメールを表示するだけで、西側組織のメールや認証情報を窃取していたことが分かった。 NSA、CISAな

    @yousukezan

    23 Jul 2026

    1667 Impressions

    1 Retweet

    4 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  43. Zimbra zero-click exploit: Ρωσική ομάδα κλέβει email και 2FA codes μέσω CVE-2025-66376 https://t.co/SAcYNTfWsV

    @SecNews_GR

    23 Jul 2026

    78 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  44. Russian state-backed LAUNDRY BEAR is exploiting CVE-2025-66376 in Zimbra Collaboration Suite with phishing to steal email data and account details from Western organizations. #Russia #Zimbra #Phishing https://t.co/FF9tWyZVjF

    @TweetThreatNews

    23 Jul 2026

    197 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  45. Russian TA488 Exploits Zimbra CVE-2025-66376 to Target Government Mail Servers  https://t.co/DXQ3QyJVbz

    @eSecurityPlanet

    23 Jul 2026

    88 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  46. Unit 42 linked CL-STA-1114 to Russian actors targeting Zimbra webmail with zero-click phishing, stealing credentials, 2FA codes, session data, and email history via CVE-2025-66376. #Russia #Zimbra #Unit42 https://t.co/mJi3BEaC6I

    @TweetThreatNews

    23 Jul 2026

    123 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  47. Zero-Click Zimbra Exploit Steals 90 Days of Email from Governments > russian threat actor Void Blizzard leverages CVE-2025-66376 to exfiltrate 90 days of email, 2FA codes, and credentials without any user interaction > unit 42 details CL-STA-1114, a Russian cyberespionage

    @0J0BIT

    23 Jul 2026

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  48. Alerta crítica en SharePoint y Zimbra: CISA añade el nuevo vector CVE-2025-66376 a su catálogo de amenazas https://t.co/iT3nHIXQ3J

    @KernelReload

    3 Apr 2026

    109 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  49. CISA KEV 警告 26/03/18:Zimbra Collaboration の脆弱性 CVE-2025-66376 を登録 https://t.co/Ds2QRm4quK Zimbra Collaboration Suite (ZCS) の深刻な脆弱性 CVE-2025-66376 が、CISA KEV カタログに登録されました。この脆弱性は、すでに実際の攻撃

    @iototsecnews

    26 Mar 2026

    149 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  50. CVE-2025-66376: Zimbra Classic UI Stored XSS - What It Means for Your Business and How to Respond https://t.co/qewYjrBaZi

    @integ_sec

    25 Mar 2026

    106 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations