Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

Published July 23, 2026 CVE-2025-66376

A Russia-linked hacking group called Laundry Bear broke into government and defense email accounts by exploiting a hidden flaw in Zimbra webmail. Just opening a rigged email let attackers silently copy months of mail, contacts, passwords, and two-factor codes.

Severity
HighCVSS 3.1 · 7.2
Fix
Update available
Affected versions
10.0 to before 10.0.18; 10.1 to before 10.1.13
Weakness
CWE-79Cross-site Scripting (XSS)
Exploit likelihood
20% in 30 daysEPSS, higher than 97% of known flaws
Affects
Collaboration
Exploited
Yes, in the wildListed by CISA
Added to CISA list
Mar 18, 2026
Federal fix deadline
Apr 1, 2026

How it works

Attackers send an email crafted so that Zimbra's Classic web interface treats part of its content as CSS style code, which lets a hidden script run the instant the email is opened, no click needed.

What to do

Check the vendor advisory or current release for the fixed version, then see whether the installed Russian Espionage version is older.

Update Russian Espionage through its normal update channel, then confirm the installed version matches the newest vendor release.

Technical details

Affected software: Collaborationby Zimbra

CVE-2025-66376 is a stored cross-site scripting flaw in Zimbra Collaboration Suite's Classic UI, triggered through CSS @import directives embedded in HTML email content, patched in outdated ZCS versions (November 2025). Since at least July 2025, Laundry Bear (tracked separately from Fancy Bear despite overlapping tradecraft) has weaponized it as a zero-click exploit: a crafted email executes JavaScript on open, without any user interaction, and exfiltrates roughly 90 days of mail, stored passwords, contact lists, and 2FA/OTP tokens from the compromised mailbox. CISA, NCSC, and partner agencies attribute the campaign to Russian state-backed espionage, with Ukrainian entities targeted first as a testbed before expansion to US and NATO government, defense-industrial, and research targets.

Severity breakdown

  • Attack vector Network Requires network access to the vulnerable service
  • Attack complexity Low Low complexity under the assessed conditions
  • Privileges required None Attacker needs no account or login
  • User interaction None No victim action needed
  • Scope Changed Impact crosses a security authority boundary
  • Confidentiality impact Low Some data can be read
  • Integrity impact Low Some data can be modified
  • Availability impact None No availability impact
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N Open in FIRST.org calculator