Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-07-24 ยท updated: 2026-07-24 ยท tags: [incident, nation-state, russia, cisa, acsc, nsa, joint-advisory, zero-day, espionage, government] ยท confidence: high ยท affected_sectors: [government, technology] ยท au_impact: true

Aa26 204A โ€” Joint Advisory on Russian Zimbra Zero-Day Campaign

A joint cybersecurity advisory published July 23, 2026 by CISA, NSA, ACSC, Palo Alto Networks Unit 42, and Proofpoint detailing a Russian state-sponsored espionage campaign exploiting a Zimbra zero-day (CVE-2025-66376).

Timeline

  • ~July 2025: Exploitation of CVE-2025-66376 begins
  • July 23, 2026: Joint advisory Aa26 204A published

Targets

Western government and commercial mailboxes using Zimbra. The campaign is part of broader Russian state-sponsored cyber espionage targeting email infrastructure.

The Exploit

The "view-based exploit" (stored XSS in Zimbra Classic UI) requires only that a victim opens a crafted HTML email. Once triggered, it abuses CSS @import handling to:

  • Exfiltrate 90 days of email content
  • Export the full Global Address List / directory
  • Steal saved browser passwords
  • Capture 2FA recovery codes

Attribution

Russian state-supported espionage group. The specific group name was not disclosed in the public advisory, but the multi-agency authorship (NSA, CISA, ACSC, Unit 42, Proofpoint) indicates high confidence state attribution.

Australian Significance

Co-published by the Australian Cyber Security Centre (ACSC), this advisory is directly applicable to Australian organisations using Zimbra. Australian government departments and commercial entities using Zimbra should:

  • Apply patches immediately
  • Audit for indicators of compromise listed in Aa26 204A
  • Review 2FA recovery code handling
  • Ensure email security monitoring covers the described TTPs

Related Pages