Exploited in the wild Zimbra Collaboration Suite Laundry Bear nation-state Zimbra rce
Russian hackers exploit unpatched Zimbra servers to steal emails
CVE Tools coverage
A Russian state-backed hacking group called Laundry Bear has been exploiting an unpatched vulnerability in Zimbra Collaboration Suite (CVE-2025-66376) to infiltrate government and corporate networks since July 2025. The flaw, a cross-site scripting issue fixed in November 2025, allows attackers to steal sensitive data simply by having users view a malicious email. Multiple U.S. and international cybersecurity agencies warn that the threat actors continue to use this exploit against unpatched systems, targeting sectors including defense, government, education, and law enforcement. Organizations are urged to apply updates and monitor for suspicious activity.