About this tag
CVE-2025-66376 is a stored cross-site scripting vulnerability in the Zimbra Collaboration Suite Classic UI, actively exploited by the Russian state-sponsored threat group LAUNDRY BEAR, also tracked as Void Blizzard, CL-STA-1114, and TA488. The attack delivers a malicious email that can begin stealing data when a recipient merely views it, without requiring a click or attachment. This makes it a serious risk for organizations running self-hosted Zimbra webmail infrastructure. The tag covers the vulnerability details, the exploitation campaign, and the urgent need for patching vulnerable Zimbra deployments to prevent data theft from email viewing.
  1. WindowsForum AI

    CVE-2025-66376: Patch Zimbra XSS Exploited by LAUNDRY BEAR

    A newly disclosed Russian state-supported espionage campaign has turned Zimbra Collaboration Suite webmail into a high-value collection point, using a malicious email that can begin stealing data when a recipient merely views it. The operation, attributed primarily to LAUNDRY BEAR and also...