Yes. An actively exploited vulnerability, CVE-2025-66376, in Zimbra Collaboration Suite can allow malicious code to run when a user simply views a crafted email in a vulnerable webmail version. For a business, this can create a risk of email disclosure, credential theft, and multi-factor authentication token theft — without the victim clicking a link or opening an attachment.
If your organisation uses Zimbra, the immediate priority is to confirm the deployed version, apply the available security update, and investigate whether infrastructure or accounts show signs of misuse. CHORS.NET provides Continuous Monitoring to help organisations continuously identify exposed services, new vulnerabilities, and risks that require action.
Key point: using Zimbra does not, by itself, mean that an incident occurred. It does mean that the installed version, use of Classic UI, and historical activity should be verified without delay.
What Is the Business Risk?
CVE-2025-66376 is a stored cross-site scripting (XSS) vulnerability in Zimbra Collaboration Suite. An attacker can embed malicious code in an HTML email and cause that code to execute in the context of an authenticated user session when the message is viewed in Classic UI.
A zero-click attack means that normal user caution — avoiding suspicious links and attachments — may not be sufficient. For leadership teams, the risk concerns business continuity, confidentiality of commercial correspondence, customer data, negotiations, documents, and access to additional systems associated with an email account.
CISA, NSA and FBI warned that the Russian threat group known as Laundry Bear used this vulnerability in a campaign targeting Western organisations, likely for espionage. The joint advisory identifies targets across government, defence, technology, education, media and non-governmental sectors.
Who Is Affected by CVE-2025-66376?
The vulnerability affects Zimbra Collaboration Suite version 10.0 before 10.0.18 and version 10.1 before 10.1.13. It is associated with the Classic UI and handling of malicious CSS @import directives in HTML email.
Treat this as a priority if your organisation:
- operates its own Zimbra server or uses a hosted Zimbra instance;
- cannot demonstrate a reliable patch-management process for its email platform;
- continues to use Classic UI;
- processes customer records, financial documents, quotes, personal data or sensitive commercial information through email;
- does not monitor email-server logs, authentication anomalies and changes to account configuration;
- does not know which systems and accounts are exposed to the public internet.
What Could an Attacker Access?
The campaign described by government agencies used a custom aggregation and data-exfiltration capability called Ulej. According to the advisory, its use could lead to the collection of sensitive user information.
Potential technical and business impacts include:
- exposure of corporate email contents;
- theft of credentials or application passwords;
- theft of MFA/2FA tokens and session data;
- access to address books and organisational information;
- use of a compromised mailbox for further phishing, business email compromise, or lateral movement;
- persistent risk if sessions, tokens and application passwords are not revoked after an incident.
The campaign did not require traditional user interaction. Viewing a malicious email in a vulnerable Zimbra version was enough, which makes prompt remediation a business-critical action rather than routine administration.
How Should You Reduce Risk Now?
Start by confirming the deployed Zimbra version and updating immediately to a release that includes the fix. For CVE-2025-66376, the remediation is available in Zimbra Collaboration Suite 10.0.18 and 10.1.13.
Administrator Action Plan
- Identify the Zimbra Collaboration Suite version and determine whether Classic UI is in use.
- Upgrade to a patched or later version, following vendor guidance and your established change-control process.
- If immediate patching is not possible, restrict use of Classic UI and use an alternative email client until the update is deployed.
- Review mail-server logs, authentication activity, abnormal mailbox actions and outbound traffic that could indicate data exfiltration.
- Inspect application passwords, active sessions, email-forwarding rules, account changes and unusual integrations.
- If indicators of compromise are identified, contain the issue under your incident-response plan: preserve evidence, revoke sessions and tokens, reset credentials, and assess the scope of exposure.
- Enable continuous monitoring of vulnerabilities and exposed services so that future critical risks do not remain undetected between periodic reviews.
Do not conduct intrusive testing against systems without proper authorisation. Production-environment verification should follow an agreed scope, change procedures and incident-response policy.
Why Patching Alone Is Not Enough
Patching is essential, but it does not answer whether a vulnerable system was already exploited. If an attacker acquired a session token, application password or mailbox access before remediation, installing the patch alone may not remove the consequences of compromise.
An effective process includes three layers:
| Area | Control question | Required action |
|---|---|---|
| Remediation | Does the installed Zimbra version include the fix? | Upgrade to a secure release and validate configuration |
| Incident validation | Are there signs of unusual logins, rules or data transfers? | Review logs, accounts, tokens, application passwords and mailbox activity |
| Ongoing risk reduction | Will the company identify the next actively exploited vulnerability in time? | Continuously monitor exposure, vulnerabilities and remediation priorities |
CHORS.NET Expert View
"For email platforms, the most consequential operational failure is not only missing a patch. It is lacking a clear answer to three questions: what is exposed to the internet, whether the vulnerability is being actively exploited, and whether evidence of prior access remains after remediation. Without those answers, an organisation is only assuming that the risk is closed."
— Marcin Białczyk, Engineer, CHORS.NET
At CHORS.NET, we treat email security as a business-risk issue: establish the exposure, assess urgency, provide actionable recommendations, and help teams structure the next steps. We do not replace internal IT teams — we help them decide faster where attention and remediation effort should go.
Frequently asked questions
Does CVE-2025-66376 affect every Zimbra installation?
No. It affects specific Zimbra Collaboration Suite releases: version 10.0 before 10.0.18 and version 10.1 before 10.1.13. However, each organisation should confirm the actual version, configuration and use of Classic UI in its own environment.
Is installing the Zimbra update enough?
The update is essential, but it does not confirm that compromise did not occur before patching. After updating, review logs, active sessions, tokens, application passwords, email-forwarding rules and unusual account activity.
What does a zero-click attack mean in Zimbra?
A zero-click attack does not require a user to click a link, download a file or enter credentials on a fake website. In this scenario, simply viewing a crafted email in a vulnerable Zimbra Classic UI version could trigger the exploit.
Can an organisation without an in-house security team assess its exposure?
Yes. Start by confirming who administers Zimbra, which version is installed, and whether the patch has been deployed. Then place email services and other internet-facing systems under an exposure and vulnerability-monitoring process to identify risks that require a decision.
Does Continuous Monitoring replace incident response?
No. Continuous Monitoring helps identify vulnerabilities, exposure and emerging risk earlier, while a detected or suspected incident requires separate response actions under an incident-response process. Monitoring reduces detection time and supports remediation prioritisation.
Check Your Email Exposure
If you use Zimbra — or are unsure which platform supports your business email — begin by establishing your internet-facing exposure and remediation priorities. Continuous Monitoring from CHORS.NET helps organisations continuously identify vulnerabilities and changes that can increase business risk.
Explore the Internet Exposure Scan service → or Vulnerability Audit →