Aa26 204A โ Joint Advisory on Russian Zimbra Zero-Day Campaign
A joint cybersecurity advisory published July 23, 2026 by CISA, NSA, ACSC, Palo Alto Networks Unit 42, and Proofpoint detailing a Russian state-sponsored espionage campaign exploiting a Zimbra zero-day (CVE-2025-66376).
Timeline
- ~July 2025: Exploitation of CVE-2025-66376 begins
- July 23, 2026: Joint advisory Aa26 204A published
Targets
Western government and commercial mailboxes using Zimbra. The campaign is part of broader Russian state-sponsored cyber espionage targeting email infrastructure.
The Exploit
The "view-based exploit" (stored XSS in Zimbra Classic UI) requires only that a victim opens a crafted HTML email. Once triggered, it abuses CSS @import handling to:
- Exfiltrate 90 days of email content
- Export the full Global Address List / directory
- Steal saved browser passwords
- Capture 2FA recovery codes
Attribution
Russian state-supported espionage group. The specific group name was not disclosed in the public advisory, but the multi-agency authorship (NSA, CISA, ACSC, Unit 42, Proofpoint) indicates high confidence state attribution.
Australian Significance
Co-published by the Australian Cyber Security Centre (ACSC), this advisory is directly applicable to Australian organisations using Zimbra. Australian government departments and commercial entities using Zimbra should:
- Apply patches immediately
- Audit for indicators of compromise listed in Aa26 204A
- Review 2FA recovery code handling
- Ensure email security monitoring covers the described TTPs
Related Pages
- Cve 2025 66376 Zimbra Xss โ The specific CVE vulnerability page
- Cisa Acsc Russian Network Devices โ Earlier Aa26 194A advisory on Russian network device targeting
- Sandworm โ Russian GRU APT (related state-sponsored context)