logo

CVE-2025-66376: Russian APT Exploits Zimbra Zero-Day

ID: f6700bd5-c99e-5878-ad2c-9786b2c1a544

STIX ID: report--f6700bd5-c99e-5878-ad2c-9786b2c1a544

Feed Name: SOCRadar Blog

Threat Score
90/100

Date Published: 2026-07-24

Date Updated: 2026-07-25

Author: ameer

...
...

CVE-2025-66376 is a stored XSS vulnerability in Zimbra Collaboration Suite Classic UI that was exploited in the wild by Russian state-aligned actors to steal mail, contacts, credentials, and 2FA/app-password material; affected versions include Zimbra 10.0 (<10.0.18) and 10.1 (<10.1.13). The report provides exploitation timeline, IoCs (domains, IPs, certificate hashes, email/sample hashes), exfiltration URL patterns, detection and hunting guidance (mailbox logs, browser localStorage, network telemetry), and recommended mitigations: immediate patching, suspend Classic UI if needed, reset credentials, revoke app passwords, and search/quarantine malicious messages.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.