Published Friday, July 24, 2026 at 09:10 AM PT

BLUF: Russian state-backed threat actors are actively exploiting a zero-click vulnerability in Zimbra Collaboration Suite to access emails and multi-factor authentication codes from unpatched servers worldwide. Targeted organizations should assume compromise if running unpatched Zimbra and take immediate containment action.

DETAILS

  • Attack Vector: Zero-click (or near-zero-click) exploitation requiring no user interaction — attackers bypass standard security warnings and phishing-resistance controls by directly compromising the mail server.

  • Threat Actor: Russian espionage group tracked as “Laundry Bear” and/or TA488 (Proofpoint designation). NSA, FBI, and Australian Cyber Security Centre are tracking this threat; ACSC has issued joint advisory.

  • Target: Zimbra Collaboration Suite mail servers, particularly instances that remain unpatched. Exploitation does not require compromised user credentials.

  • What’s Stolen: Full email access (inbox/sent/archives) and two-factor authentication codes, enabling follow-on credential compromise and lateral movement.

  • Scope: Western government and commercial organizations confirmed as targets. Unknown whether exploitation is opportunistic or targeted by organization type.

IMPACT

  • Immediate: Any organization running unpatched Zimbra Collaboration Suite is actively at risk. Compromised accounts grant attackers persistent mail access and bypass of modern MFA schemes.
  • Secondary: 2FA codes enable account takeover of external services and cloud platforms, expanding blast radius beyond email.
  • Uncertainty noted: Total number of compromised organizations and servers is not publicly disclosed; threat actors may be maintaining quiet access on high-value targets.
  1. Urgent: Verify Zimbra Collaboration Suite version and patch status. Apply all available security updates immediately.
  2. Detect: Check mail server logs for unusual authentication patterns, forwarding rules, or data exfiltration; assume compromise if Zimbra is unpatched.
  3. Contain: If unpatched, isolate from network until patched, or reset all associated user credentials and re-issue 2FA tokens.
  4. Monitor: Watch for secondary intrusions on accounts/services that rely on compromised mail and 2FA codes.

SOURCES

  • Proofpoint: TA488 Targets Zimbra Mailservers with Half-Click Exploits (NSA/FBI coordination)
  • Australian Cyber Security Centre: Joint advisory on Russian cyber actors exploiting Zimbra Collaboration Suite
  • BleepingComputer, The Hacker News, CyberScoop, Help Net Security (coordinated reporting)

Recent high-severity events at publish time:

Recent high-severity events