(TLP:CLEAR) CISA Advisory – Russian State-Supported Actors Exploit Zimbra Zero-Day in Ongoing Phishing and Espionage Campaign
Created: Thursday, July 23, 2026 - 15:09
Categories: Cybersecurity, Federal & State Resources, Security Preparedness
(TLP:CLEAR) CISA Advisory – Russian State-Supported Actors Exploit Zimbra Zero-Day in Ongoing Phishing and Espionage Campaign
ACTION MAY BE REQUIRED for utilities using self-hosted Zimbra Collaboration Suite (ZCS) webmail, particularly deployments running versions prior to 10.1.13 or 10.0.18. Utilities that outsource technology support may need to consult their service providers for assistance with remediation actions.
Summary: Today, CISA, NSA, FBI, and more than 20 international partners released a joint advisory detailing an ongoing campaign by the Russian state-supported group tracked as LAUNDRY BEAR (also Void Blizzard) against users of Zimbra Collaboration Suite (ZCS).
Since at least July 2025, the actors have exploited CVE-2025-66376, a cross-site scripting flaw that was a zero-day when first used (and remained a zero-day for months) until a patch was released in November 2025 for ZCS versions 10.1.13 and 10.0.18. This vulnerability and subsequent exploitation are extremely dangerous. The exploit requires no clicking, and simply viewing a malicious email in a vulnerable webmail client triggers a JavaScript payload that steals 90 days of email, the Global Address List, 2FA scratch codes, and passwords, then establishes persistence by enabling IMAP and creating an Application Passcode named “ZimbraWeb.”
Analyst Note: Utilities running self-hosted ZCS are exposed to the same risk as any other Western organization, and the intelligence value of a utility email inbox is real. Stolen address lists and message history support convincing follow-on phishing against operations staff, engineering firms, and integrators.
WaterISAC strongly encourages impacted members review the advisory and mitigations section. Additionally, the following steps can help secure ZCS deployments and identify whether the campaign has already reached a utility’s mailboxes:
- Confirm ZCS is patched, and direct staff to alternative mail clients if patching is delayed.
- Review /opt/zimbra/log/mailbox.log for bursts of SearchGalRequest, GetScratchCodesRequest, or CreateAppSpecificPasswordRequest activity.
- Revoke Application Passcodes and 2FA scratch keys where compromise is suspected.
WaterISAC encourages members to report any related findings to an*****@*******ac.org.
Original Source: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a
Additional Reading:
- Russia-backed threat actor targets Western organizations in phishing campaign
- Russian Global Webmail Espionage
- TA488 Targets Zimbra Mailservers with Half-Click Exploits
Related WaterISAC PIRs: 6, 7, 7.1, 8, 10, 10.2, 12
