Skip to content

CVE-2025-27915

CVE

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
March 18, 2026
Last Seen
July 24, 2026
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

Since July 2025, Russian state-backed hackers, known as Laundry Bear, have exploited a zero-click vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite to infiltrate Western government and commercial organizations. This attack method allows hackers to steal sensitive data without requirin...

Russian state-backed hackers from APT28 are actively exploiting a high-severity stored cross-site scripting vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite (ZCS) to target Ukrainian government entities. The flaw allows unauthenticated attackers to execute remote code and harvest sen...

Public Exploits

Checking GitHub for proof-of-concept code…