Web_Logo
Remote Support
Security Alert: Russian Hackers Exploit Zimbra Email Flaw
Home » Security Alerts  »  Security Alert: Russian Hackers Exploit Zimbra Email Flaw

Security Alert: Russian Hackers Exploit Zimbra Email Flaw

US and Australian cyber security agencies have issued a joint warning that a Russian state-backed hacking group, tracked as LAUNDRY BEAR, is actively exploiting a flaw in Zimbra Collaboration Suite webmail to steal emails, passwords and two-factor authentication codes.

  • What it is: The group is exploiting CVE-2025-66376, a flaw in how Zimbra webmail handles email formatting. Simply viewing a malicious email in a vulnerable, unpatched Zimbra inbox can trigger the exploit, no click required.
  • Who is affected: Organisations running Zimbra Collaboration Suite webmail that have not applied the November 2025 security patch. More than ten organisations have already had data stolen.
  • The risk: Attackers can silently harvest inbox contents, login credentials and two-factor authentication tokens, giving them ongoing access to email accounts.
  • What to do: Confirm your Zimbra environment is on the latest patched version, and review mailbox access logs for anything unusual if you have not patched recently.

If you are not sure which email platform your business runs or whether it is up to date, we recommend getting it checked rather than assuming it is covered.

Source: CISA Advisory AA26-204A and cyber.gov.au.