Published Thursday, July 23, 2026 at 09:02 AM PT

<strong>Russian State Actors Exploit Zimbra Zero-Day in Active Phishing Campaign โ€” All ZCS Deployments at Immediate Risk</strong>

BLUF: Russian state-sponsored cyber actors are actively exploiting CVE-2025-66376, a zero-day vulnerability in Zimbra Collaboration Suite (ZCS), via phishing campaigns to compromise user accounts. The attack chain leverages pass-the-cookie techniques for post-exploitation access. Organizations running ZCS must immediately patch or isolate affected instances; credentials for ZCS-authenticated users should be treated as potentially compromised.

DETAILS:

  • Vulnerability: CVE-2025-66376 (ZCS zero-day); publicly exploitable, initially zero-day status, continues active exploitation in the wild
  • Attack vector: Phishing emails targeting ZCS users; successful exploitation grants initial access to mail infrastructure
  • Post-exploitation: Actors employ pass-the-cookie attacks to enable high-volume, persistent operations within the environment
  • Attribution: Russian state-supported threat actors (GRU assessment aligns with concurrent targeting of logistics and technology sectors per CISA separate alert)
  • Status: Campaign is ongoing with demonstrated success rate; no indication of exploit availability constraints

IMPACT:

  • Any organization using Zimbra Collaboration Suite is in scope
  • Compromised accounts grant attackers mail access, potential lateral movement to internal systems, credential harvesting
  • Phishing emails bypassing ZCS controls (if unpatched) enable attacker foothold without additional exploitation
  • Scope includes U.S. and international organizations; sectors currently targeted include technology and critical infrastructure

RECOMMENDED ACTIONS:

  1. Immediate: If running Zimbra Collaboration Suite, apply vendor security patch immediately. If patch timeline exceeds 24 hours, isolate ZCS from network or enable IP-based access controls restricting login sources
  2. Credential review: Audit ZCS login logs for suspicious access patterns; force password reset for all ZCS users
  3. Network monitoring: Alert on anomalous mail forwarding rules, mailbox delegation changes, or pass-the-cookie indicators (session token replay from unusual IPs/user-agents)
  4. Phishing defense: Brief users on expected phishing tactics; consider temporary mail gateway rules blocking external mail claiming internal ZCS origin

SOURCES: CISA Alert (active), UK NCSC advisory (collaborative attribution), CVE-2025-66376 record


Recent high-severity events at publish time:

Recent high-severity events