CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2025-66376

criticalknown exploitedcovered by 2 sourcesfirst seen 2026-03-18
Actively exploited. CVE-2025-66376 is listed in the CISA Known Exploited Vulnerabilities catalog (added 2026-03-18) — exploitation has been observed in the wild, and US federal agencies are required to remediate it under BOD 22-01. Treat patching as urgent.
Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite Executive summary A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS) software since at least July 2025. The Russian state-supported advanced persistent threat (APT) group’s activity is tracked in the cybersecurity community under several names (see Cybersecurity industry tracking ), primarily as “LAUNDRY BEAR,” a name initially coined by the Netherlands General Intelligence and Security Service (AIVD) and Defence Intelligence and Security Service (MIVD) [ 1 ]. LAUNDRY BEAR’s targeting is almost certainly to gather sensitive information for the Russian Federation, with these actors primarily focusing on the covert acquisition of email data. Previous campaigns indicated LAUNDRY BEAR relied on unsophisticated initial access techniques—including password spraying, phishing, and pass-the-cookie—allowing the group to successfully run high-volume operations. The latest campaign targeting ZCS uses a novel exploit that was a zero-day vulnerability when first exploited and continues to be successfully exploited. The vulnerability, Common Vulnerabilities and Exposures (CVE) CVE-2025-66376 , was patched in November 2025. This demonstrates LAUNDRY BEAR’s intent and ability to deploy increasingly sophisticated technical capabilities. Unlike traditional phishing campaigns that persuade a user into taking an action, such as clicking a link or opening a file, LAUNDRY BEAR’s latest campaign leverages a view-based exploit that only requires a user to view a malicious email within a vulnerable version of the webmail service. Once viewed, the exploit attempts to exfiltrate the victim’s last 90 days of email communications, the organization email directory (i.e., Global Address List [GAL]), and other sensitive information to servers controlled by LAUN

CSIRTS triage

What
Russian state-supported cyber actors are conducting phishing campaigns targeting users of the Zimbra Collaboration Suite.
Who is affected
Users of Zimbra Collaboration Suite, particularly in Western government and commercial organizations.
Urgency
Remediation is urgent due to confirmed exploitation and high severity of the threat.
Action
Organizations should enhance their security measures and monitor for phishing attempts.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2025-66376

Get an email if CVE-2025-66376 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2025-66376

CVE.org record

CISA KEV catalog

Embed the live status

CVE-2025-66376 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2025-66376 status](https://www.csirts.com/badge/CVE-2025-66376)](https://www.csirts.com/cve/CVE-2025-66376)