Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite

Randy Leiker randy at skywaynetworks.com
Thu Jul 23 18:11:50 CEST 2026


Hi Everyone, 

For the benefit of awareness of those subscribed to the Zeta Alliance mailing list, here is a advisory released today by CISA in the US related to active exploitation of vulnerabilities in Zimbra: [ https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a | https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a ] 

This advisory includes indicators of compromise you can use for checking your own Zimbra servers, and shares this advice: 

According to the National Vulnerability Database (NVD), CVE-2025-66376 was initially published on 5 January 2026. This vulnerability allows for execution of a JavaScript payload included in email content due to improper sanitization of Cascading Style Sheet’s (CSS) @import directives within an email [5]. Because the activity attributed to this campaign began in July 2025—months before Synacor released a patch and the CVE was published—the payload initially exploited a zero-day vulnerability at that time [T1587.004]. 


Randy Leiker ( randy at skywaynetworks.com ) 
Skyway Networks, LLC 
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.zetalliance.org/pipermail/users_lists.zetalliance.org/attachments/20260723/78787680/attachment.html>


More information about the Users mailing list