Skip to content
Russian attackers exploit zero-click vulnerability in Zimbra

Russian attackers exploit zero-click vulnerability in Zimbra

Heise.De • July 24, 2026

Zimbra's collaboration software, which combines email, calendar, and other functions, regularly contains security vulnerabilities that developers address with updates. Admins are apparently still installing these very hesitantly, as international (IT) security authorities are now jointly warning of attacks by Russian actors who have been exploiting a zero-click vulnerability in Zimbra since at least July 2025, among other things. The targets of the attacks are said to include Western governments, commercial and educational institutions, the energy sector, law enforcement, media, non-governmental organizations, and the technology sector.

Among others, the US cybersecurity agency CISA is currently warning this on its website . In particular, the criminal group Laundry Bear (other names: Void Blizzard, CL-STA-1114 or TA488 and UNK_PitStop) is said to be collecting confidential information for the Russian government, with a primary focus on emails. While the cyber gang previously relied on less sophisticated techniques such as password spraying, phishing, and pass-the-cookie (session cookie theft), in recent campaigns it is using a zero-day vulnerability in ZCS ( CVE-2025-66376 , CVSS 7.2 , Risk “ high ”). Victims no longer even need to click on a malicious link; simply displaying the email is enough to exploit the vulnerability and grant attackers unauthorized access to the emails.

Zimbra developers closed the security vulnerability in November 2025 with updated software. In January of this year, the Federal Office for Information Security (BSI) also warned that around 40 percent of 1500 Zimbra servers in Germany are running unsupported software versions or are vulnerable to known security flaws. Attacks on the CVE-2025-66376 vulnerability have been known since mid-March at the latest.

According to CISA's list, various international authorities are urging admins to update Zimbra software. CISA also provides a list of indicators of successful attacks (Indicators of Compromise, IOC).

Zimbra has now released version 10.1.20. It closes several security vulnerabilities, some still without CVE entries , and all without a CVSS risk assessment. IT managers should update their ZCS instances to this version to reduce the attack surface.

This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.

Extracted Entities