type: cve ยท created: 2026-07-24 ยท updated: 2026-07-24 ยท tags: [cve, zero-day, kev, xss, email, government] ยท confidence: high ยท severity: not-rated ยท affected_sectors: [government, technology] ยท au_impact: true
CVE-2025-66376 โ Zimbra Classic UI Stored XSS
CVE-2025-66376 is a stored cross-site scripting (XSS) vulnerability in Zimbra's Classic UI that has been exploited in the wild as a zero-day by a Russian state-sponsored espionage group since at least July 2025.
Details
| Field | Detail |
|---|---|
| CVE | CVE-2025-66376 |
| Type | Stored XSS (view-based exploit) |
| Component | Zimbra Classic UI / CSS @import handling |
| Exploitation | Triggers when a user opens a crafted HTML email |
| Discovered | Exploited since ~July 2025 |
| Advisory | Aa26 204A (CISA/NSA/ACSC joint advisory) |
Impact
The view-based exploit activates when a recipient opens a maliciously crafted HTML email that abuses CSS @import handling. Successful exploitation enables the attacker to:
- Exfiltrate 90 days of email from the victim's mailbox
- Extract the full directory (Global Address List)
- Steal saved browser passwords from the Zimbra session
- Capture 2FA recovery codes, enabling persistent access
- Full mailbox compromise of Western government and commercial systems
Advisory & Attribution
A joint advisory โ Aa26 204A โ was published July 23, 2026 by: - CISA (US Cybersecurity and Infrastructure Security Agency) - NSA (National Security Agency) - ACSC (Australian Cyber Security Centre) - Palo Alto Networks Unit 42 - Proofpoint
Attribution: A Russian state-supported espionage group (specific group not named in public advisory).
Related Pages
- Aa26 204A Russian Zimbra Campaign โ The joint advisory incident page
- Cisa Acsc Russian Network Devices โ Earlier joint advisory on Russian targeting of network devices (Aa26 194A)
- Sandworm โ Russian GRU APT (context on Russian state-sponsored cyber activity)