Back to Articles
high

HIGH: Russian Spies Turned a Medium-Severity Zimbra Bug Into a 2FA Heist

Russian state-supported actor LAUNDRY BEAR (Void Blizzard) exploited a zero-click Zimbra Collaboration XSS flaw, CVE-2025-66376, as a zero-day for months, stealing 90 days of email, Global Address Lists, saved passwords, and 2FA recovery codes from NATO and Ukrainian targets before minting rogue application passwords for persistent MFA-bypassing access. Patched in November 2025 and now on the CISA KEV list.

By Danny Mercer, CISSP — Lead Security Analyst Jul 24, 2026
Is your business exposed? Our McKinney-based security team can assess your risk for free.
Share:

If you run Zimbra and you have been putting off that November patch, this is the part where I tell you the Russians already found the door you left open.

Western cyber agencies, led by the NSA and CISA and joined by partners across the NATO alliance, went public this week with a joint advisory detailing a long running espionage campaign that turned a single cross site scripting flaw in Zimbra Collaboration into a full blown mailbox looting operation. The vulnerability, tracked as CVE-2025-66376, is the kind of bug that looks unremarkable on paper and turns catastrophic in the hands of a patient nation state operator. It carries a CVSS score of only 6.1, which lands it squarely in medium territory on the National Vulnerability Database, and if you judged risk by that number alone you would have slept fine. The problem is that CVSS measures the bug and not the adversary, and the adversary here spent at least five months of 2025 using it as an unknown zero day before anyone at Zimbra knew it existed.

Here is what actually happened. The flaw lives in Zimbra's Classic web interface, where the mail client fails to properly sanitize CSS @import directives buried inside HTML email messages. An attacker crafts a message that smuggles JavaScript in through that @import handling, and when the victim simply opens the email in the Classic UI, the script executes inside their authenticated webmail session. There is no attachment to open, no link to click, no macro to enable. Viewing the message is the entire attack. Researchers have described it as effectively zero click, and for a defender that distinction matters enormously, because every piece of user awareness training you have ever paid for assumes the user has to do something wrong. Here they just had to read their mail.

Once that JavaScript fired, the operators deployed a payload that researchers are calling ZimReaper, and it was built for one thing, which is emptying a mailbox quietly and completely. It reached out and grabbed the last ninety days of email, then pulled the organization's entire Global Address List, which is essentially a directory of every employee and contact in the company. It scraped saved passwords out of the browser session and lifted CSRF tokens to keep acting on the victim's behalf. Most damaging of all, it went after the two factor authentication recovery codes, the scratch codes people generate once and forget in a drawer, and it used what it stole to mint fresh application passcodes. Those app passwords let the attackers reconnect through legacy email clients that quietly sidestep multi factor authentication entirely, which means that even after a password reset the spies could still be sitting inside the mailbox reading everything that arrived.

The group behind this goes by a small pile of names depending on which vendor you read, and that alone tells you how much attention it has attracted. Palo Alto Networks' Unit 42 tracks it as CL-STA-1114, Proofpoint calls it TA488, and it also travels under the community handles LAUNDRY BEAR and Void Blizzard. Whatever you call it, the attribution points at Russian state supported espionage, and the target list reads exactly like a Russian intelligence collection wish list. The advisory names the Defense Industrial Base, federal and local government, energy, technology, education, media, law enforcement, and non governmental organizations, spread across NATO member states and Ukraine. This is not a smash and grab for cryptocurrency. This is methodical intelligence gathering against the governments and companies that support the alliance, and it has been running since at least July of 2025.

The timeline is worth sitting with for a moment, because it explains why the agencies felt the need to shout about a medium severity bug. Proofpoint assesses that the actors were exploiting this as a true zero day for months before Zimbra had any idea, silently reading the mail of Western targets while the vulnerability had no CVE, no patch, and no name. Zimbra shipped a fix on November 6, 2025, folding the correction into Zimbra Collaboration 10.0.18 and 10.1.13. Then, in a detail that should make every administrator wince, CISA did not add CVE-2025-66376 to its Known Exploited Vulnerabilities catalog until March 18, 2026, more than four months after the patch existed. That gap is exactly the window that separates organizations who patch on vendor advisories from organizations who wait for a government mandate, and in this campaign that window was measured in stolen mailboxes.

So what do you actually do about it. The first and most obvious move is to get current, which means anything running Zimbra Collaboration 10.0 needs to be on 10.0.18 or later and anything on the 10.1 branch needs 10.1.13 or later. If you are still nursing an older major version along, treat that as its own emergency, because you are missing far more than this one fix. Patching alone is not enough here though, and this is the part administrators keep getting wrong. Because the attackers created their own application passcodes for persistence, updating the software does nothing to evict them. You have to go into every potentially affected account, revoke any application specific passwords you did not explicitly authorize, and force a reset of credentials and two factor secrets for anyone whose mailbox may have been touched. The recovery codes are compromised too, so regenerating them is not optional.

Beyond eviction comes detection, and the good news is that this campaign leaves fingerprints if you know where to look. Comb your authentication logs for logins from legacy or IMAP style clients that suddenly appeared, especially ones riding application passwords that bypass MFA, because that is the persistence mechanism in action. Look for bulk access to the Global Address List and for accounts that pulled ninety days of mail in a compressed window, which is not how normal humans read email. The agencies also flagged adversary in the middle phishing kits impersonating Zimbra login portals running alongside the XSS exploitation, so any employee reports of odd Zimbra login pages deserve real investigation rather than a shrug. And if you have the option, moving users off the Classic UI to the modern interface removes the specific attack surface this exploit depends on, which is a reasonable defensive posture even after patching.

The uncomfortable lesson threaded through this whole episode is that severity scores lie by omission. A 6.1 cross site scripting bug in a webmail client is the sort of thing that dies at the bottom of a patch queue behind a dozen scarier looking numbers, and a Russian intelligence service turned it into months of undetected access to the inboxes of NATO governments. Real risk is the product of the flaw and the person holding it, and no CVSS calculator has a field for motivated adversary.

For the MSPs reading this, there is a genuine conversation to have with any client running self hosted collaboration platforms like Zimbra, and it is not a fear pitch, it is a maturity pitch. This is the perfect anchor for selling managed patch and vulnerability management as a subscription rather than a fire drill, because the four month gap between vendor fix and government mandate is precisely the risk a managed service eliminates. Pair that with a threat hunting or compromise assessment engagement focused on mailbox persistence and rogue application passwords, and you have a natural upsell into darkweb monitoring and identity protection for clients who now understand, viscerally, that stolen two factor recovery codes are worth more than stolen passwords.

References

Concerned about this threat?

Our security team can assess your exposure and recommend immediate actions.

Get a Free Assessment →