Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
A Russia-linked hacking group called Laundry Bear broke into government and defense email accounts by exploiting a hidden flaw in Zimbra webmail. Just opening a rigged email let attackers silently copy months of mail, contacts, passwords, and two-factor codes.
- Severity
- HighCVSS 3.1 · 7.2
- Fix
- Update available
- Affected versions
- 10.0 to before 10.0.18; 10.1 to before 10.1.13
- Weakness
- CWE-79Cross-site Scripting (XSS)
- Exploit likelihood
- 20% in 30 daysEPSS, higher than 97% of known flaws
- Affects
- Collaboration
- Exploited
- Yes, in the wildListed by CISA
- Added to CISA list
- Mar 18, 2026
- Federal fix deadline
- Apr 1, 2026
How it works
Attackers send an email crafted so that Zimbra's Classic web interface treats part of its content as CSS style code, which lets a hidden script run the instant the email is opened, no click needed.
What to do
Check the vendor advisory or current release for the fixed version, then see whether the installed Russian Espionage version is older.
Update Russian Espionage through its normal update channel, then confirm the installed version matches the newest vendor release.
Technical details
Affected software: Collaborationby Zimbra
CVE-2025-66376 is a stored cross-site scripting flaw in Zimbra Collaboration Suite's Classic UI, triggered through CSS @import directives embedded in HTML email content, patched in outdated ZCS versions (November 2025). Since at least July 2025, Laundry Bear (tracked separately from Fancy Bear despite overlapping tradecraft) has weaponized it as a zero-click exploit: a crafted email executes JavaScript on open, without any user interaction, and exfiltrates roughly 90 days of mail, stored passwords, contact lists, and 2FA/OTP tokens from the compromised mailbox. CISA, NCSC, and partner agencies attribute the campaign to Russian state-backed espionage, with Ukrainian entities targeted first as a testbed before expansion to US and NATO government, defense-industrial, and research targets.
Severity breakdown
- Attack vector Network Requires network access to the vulnerable service
- Attack complexity Low Low complexity under the assessed conditions
- Privileges required None Attacker needs no account or login
- User interaction None No victim action needed
- Scope Changed Impact crosses a security authority boundary
- Confidentiality impact Low Some data can be read
- Integrity impact Low Some data can be modified
- Availability impact None No availability impact
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N Open in FIRST.org calculatorReferences
- wiki.zimbra.com · Security_Center Release Notes Vendor Advisory
- wiki.zimbra.com · 10.0.18 (10.0.18) Release Notes
- wiki.zimbra.com · 10.1.13 (10.1.13) Release Notes
- wiki.zimbra.com · Zimbra_Responsible_Disclosure_Policy Product
- wiki.zimbra.com · Zimbra_Security_Advisories Vendor Advisory
- cisa.gov · known-exploited-vulnerabilities-catalog US Government Resource
- scworld.com · russian-hackers-exploited-zimbra-zero-day-in-espionage-campaigns SC World
- darkreading.com · russian-hackers-zimbra-zero-day-us-ukraine-targets DarkReading