Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes — [https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjzlA3Ln3fk8yzrfLwR

russian-espionage-group-exploited-zimbra-zero-day-to-steal-mail-and-2fa-codes

What’s new: A Russian state-supported espionage group exploited a zero-day vulnerability (CVE-2025-66376) in Zimbra’s webmail client to access Western email accounts. The flaw, a stored cross-site scripting vulnerability, allowed attackers to steal emails, passwords, and two-factor authentication codes simply by the victim viewing a malicious email. The vulnerability affected Zimbra Collaboration versions 10.0 before 10.0.18 and 10.1 before 10.1.13. Zimbra released a patch on November 6, 2025, and CISA added it to the Known Exploited Vulnerabilities catalog on March 18, 2026.

Who’s affected

Organizations in government, defense, transportation, and finance sectors across NATO member states, Ukraine, the Commonwealth of Independent States, and Africa are at risk. Specific U.S. entities, including those in the scientific and defense industrial base, have also been targeted.

What to do

  • Upgrade Zimbra to at least version 10.1.13 or migrate from unsupported 10.0 versions to a supported 10.1 build.
  • Reset passwords and invalidate active sessions for any accounts that opened or previewed a malicious email.
  • Regenerate two-factor authentication scratch codes for affected accounts.
  • Review logs for any unauthorized creation of app-specific passwords and remove any named ZimbraWeb.
  • Check for accounts with IMAP enabled that do not require it and disable as necessary.
  • Monitor for unusual SOAP calls and filter DNS for known command-and-control domains.

Sources