CISA, NSA, FBI Flag Russian Zero-Click Zimbra Exploit
A zero-click vector requiring no user action, coupled with custom Ulej exfiltration tooling targeting DIB and government organizations, makes this dedicated Russian espionage, not opportunistic exploitation.
TL;DR
CISA, NSA, and the FBI issued a joint advisory Wednesday warning that Russian APT LAUNDRY BEAR is actively exploiting CVE-2025-66376, a zero-click vulnerability in Zimbra Collaboration Suite that requires no user interaction beyond viewing a malicious email. Since July 2025, more than 10 organizations, including DIB contractors, federal and local government, and law enforcement, have been hit. The group uses a custom exfiltration tool called Ulej to harvest email credentials and two-factor authentication tokens. CVE-2025-66376 has been on CISA's Known Exploited Vulnerabilities list since March. The joint NSA-FBI escalation signals that the KEV listing alone wasn't closing the remediation gap.
The joint advisory, designated AA26-204A, describes a campaign by the Russian APT group publicly tracked as LAUNDRY BEAR that exploits CVE-2025-66376, a cross-site scripting vulnerability in the Zimbra Collaboration Suite webmail service. Unlike phishing campaigns that depend on convincing a user to click a link or download an attachment, this exploit fires when the target merely views a malicious email in a vulnerable ZCS instance. No click. No download. The email loads, the exploit executes, and the attacker is in.
That's the operational distinction that matters. Most phishing defense assumes the user has to do something wrong. Here, the user does nothing wrong and still gets compromised.
LAUNDRY BEAR deploys a custom-developed aggregation and exfiltration capability the advisory names Ulej to harvest email credentials and two-factor authentication tokens from compromised ZCS instances. Custom tooling is expensive to develop and maintain; it signals a dedicated espionage program, not actors repurposing off-the-shelf malware. Since July 2025, more than 10 organizations have been successfully targeted, spanning the Defense Industrial Base, federal and local government, law enforcement, technology, education, media, and non-governmental organizations. The target set is exactly what you'd expect for a Russian intelligence collection effort.
CVE-2025-66376 was added to CISA's Known Exploited Vulnerabilities catalog on March 18, 2026, which triggers Binding Operational Directive 22-01 remediation requirements for federal civilian agencies. The four-month gap between the KEV listing and Wednesday's joint NSA-FBI advisory suggests the initial patch-and-move-on guidance wasn't closing the gap.
This is at least the third time since 2022 that CISA has issued a Zimbra-focused advisory. The August 2022 advisory, AA22-228A, covered multiple CVEs being chained against ZCS and was updated repeatedly through January 2023. For organizations still running Zimbra, the pattern is clear: the platform remains a high-value target for both nation-state and criminal actors, and patch latency is the attack surface.
Organizations running ZCS should patch immediately if they haven't since March and hunt for indicators of compromise using the signatures in AA26-204A. If your instance was internet-facing and unpatched between the March KEV listing and now, active exploitation over a four-month window means patching alone isn't enough.
Published ·Deep Fathom