A Zimbra XSS zero-day let a Russian espionage group read mailboxes and steal 2FA codes for months
NSA, CISA, and partner agencies detailed a year-long campaign against Zimbra Classic UI, tracked under several names including Void Blizzard and LAUNDRY BEAR, that pulled 90 days of mail, browser-saved passwords, and two-factor recovery codes from an authenticated session.
A joint advisory from NSA, CISA, and partner agencies, published July 23, 2026, details a campaign that started in July 2025 and ran into February 2026 against Zimbra's Classic UI. The bug, CVE-2025-66376, is a stored cross-site-scripting flaw: a target only had to view a malicious email for JavaScript to execute inside their already-authenticated session, no click, no credential entry. From there the actor pulled the last 90 days of mail, the organization's full address directory, passwords saved in the browser, and two-factor recovery and scratch codes. Targets spanned NATO governments, Ukraine, the CIS, and African, US government, scientific, and defense-industrial entities including nuclear facilities. Zimbra patched in Collaboration 10.0.18 and 10.1.13 (current is 10.1.20); CISA added the CVE to its Known Exploited Vulnerabilities catalog on March 18, 2026.
Why it matters
Stealing MFA recovery codes alongside mail is the detail worth sitting with: it converts a one-time mailbox read into durable re-entry, because scratch codes are exactly the fallback that bypasses whatever second factor you rolled out after the first compromise. A stored XSS in a webmail client turns "authenticated session" into the attacker's credential, no phishing page, no token theft technique needed beyond a viewed email.
If Zimbra is in your stack, confirm you're on 10.1.13 or later specifically, not just "patched at some point," and treat any 2FA recovery codes issued before your patch date as burned.
Source: The Hacker News
Related on Start with Identity
- BlogA SharePoint JWT validation bug let unauthenticated attackers become any user, including admins
CVE-2026-55040 (CVSS 9.1) let a remote, unauthenticated attacker who knows a target's Active Directory SID or user principal name forge a valid session as that
- BlogA Check Point SmartConsole flaw hands out full admin tokens to unauthenticated attackers
CVE-2026-16232 (CVSS 9.3) lets an unauthenticated remote attacker obtain an application login token for Check Point Security Management and Multi-Domain Managem
- BlogForged OIDC tokens in SimpleHelp RMM handed out technician access to 1,000 exposed servers, no MFA required
CVE-2026-48558 lets an unauthenticated attacker forge OpenID Connect tokens against SimpleHelp remote-monitoring software configured for group login, gaining pr
- CVEZimbra ZCS chained with CVE-2025-48700 to steal MFA backup codes
Zimbra Collaboration Suite, chained with CVE-2025-48700, was used to steal MFA backup codes and app passwords (CERT-UA UAC-0233). Added to CISA KEV in mid-March
- RankingBest Zero Trust Tools: Top 5 ZTNA and SSE Platforms
The top 5 Zero Trust tools (Cloudflare, Zscaler, Tailscale, Palo Alto Prisma Access, Netskope), scored on a 10-dimension rubric.
- VendorCloudflare Zero Trust
top_tier