Zimbra Webmail is a technology platform tracked by ThreatCluster, appearing in 3 threat clusters built from 3 intelligence report mentions.
Zimbra Webmail is a technology platform tracked across 3 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed January 30, 2026; most recent activity July 24, 2026.
A Russian state-linked advanced persistent threat (APT) has targeted a Ukrainian government agency through a cross-site scripting (XSS) vulnerability in the Zimbra Collaboration Suite, identified as CVE-2025-66376. The…
Russian threat actors TA488 and TA458 are exploiting vulnerabilities in webmail servers, specifically targeting Ukrainian entities and government sectors. TA488 utilizes a half-click exploit via CVE-2025-66376 in Zimbra…
A Local File Inclusion (LFI) vulnerability (CVE-2025-68645) has been identified in the Zimbra Collaboration Suite Webmail Classic UI, allowing unauthenticated attackers to exploit user-supplied request parameters.…
Zimbra Webmail is a technology platform tracked by ThreatCluster, appearing in 3 threat clusters built from 3 intelligence report mentions.
The most recent intelligence report mentioning Zimbra Webmail on ThreatCluster is dated July 24, 2026. Activity was first observed January 30, 2026, giving a tracked span from then to July 24, 2026.
Across ThreatCluster reporting, Zimbra Webmail most frequently co-occurs with Apt28, BlueDelta, Fancy Bear, Sofacy Group, Strontium, among 12 tracked related entities.
The most significant recent cluster is “Russian APT Exploits Zimbra XSS to Target Ukrainian Government” (4 articles · Updated March 20, 2026). Zimbra Webmail appears across 3 threat clusters in total, listed above with sources.
Zimbra Webmail appears in 3 intelligence report mentions across 3 deduplicated threat clusters, aggregated from 17,000+ monitored sources.