Published Thursday, August 20, 2026 at 04:45 AM PT

BLUF
Russian state-backed group “Laundry Bear” is actively exploiting a critical remote code execution vulnerability in Zimbra Collaboration Suite. Malicious code embedded in crafted emails executes in user sessions. All unpatched ZCS deployments are compromised. Patch immediately; treat as active intrusion risk.
DETAILS
- Vulnerability: Critical RCE flaw in Zimbra Collaboration Suite allows arbitrary code execution via specially crafted emails; executes in user session context.
- Active Exploitation: Russian state actors (identified as “Laundry Bear”) confirmed conducting phishing campaigns against Western government and critical infrastructure targets. Pass-the-cookie techniques documented for session hijacking and persistence.
- Affected Scope: All Zimbra Collaboration Suite deployments without current patches. Vulnerability described as zero-day/zero-click variant in some reporting.
- Confirmed Attacks: High-volume successful intrusions documented. CISA has issued formal alerts. Multiple independent sources (BleepingComputer, SecurityWeek, The Hacker News, Help Net Security, Industrial Cyber) confirm active exploitation in the wild.
- Attack Path: Phishing + malicious email β RCE β session hijacking β lateral movement and data theft.
IMPACT
- Who: Organizations running any unpatched Zimbra Collaboration Suite instance.
- What: Remote code execution, email compromise, credential theft, unauthorized lateral movement into internal networks.
- Scope: Government agencies, critical infrastructure operators, and broader enterprise targets currently under active attack.
- Severity: Exploitation is in-the-wild, not theoretical. Successful intrusions already reported.
RECOMMENDED ACTIONS
- Immediate: Patch all Zimbra Collaboration Suite systems to current security release without delay.
- Urgent: Review email logs (30β60 days retroactive) for suspicious crafted emails or anomalous payloads; coordinate with security team.
- Active Defense: Monitor for pass-the-cookie indicators (unusual session activity, impossible travel, off-hours access).
- If Patching Delayed: Isolate unpatched systems from internal network; disable external mail relay if feasible.
- Incident Response: Contact CISA for indicators of compromise (IOCs) and cross-check logs; assume compromise if system remained unpatched >7 days.
SOURCES
news4hackers, BleepingComputer, SecurityWeek, The Hacker News, Help Net Security, CISA Alerts, Industrial Cyber
Recent high-severity events at publish time:

