Exploited in the wild Zimbra Collaboration Suite Laundry Bear nation-state Zimbra TA488
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
CVE Tools coverage
A Russian state-backed hacking group has been exploiting a zero-day vulnerability in Zimbra's webmail client to steal sensitive data, including email archives and two-factor authentication (2FA) recovery codes. The flaw, CVE-2025-66376, allows attackers to execute malicious JavaScript simply by viewing a crafted HTML email. This vulnerability was actively used between July 2025 and February 2026 against government and commercial organizations in Western countries, Ukraine, and other regions. Zimbra released patches for affected versions in November 2025, but users must manually review compromised accounts and invalidate stolen credentials.