Vulnerabilities & Exploits
Zimbra Patches Linger While Mailboxes Stay Readable The break is not the XSS alone. It is that patched Zimbra servers still left mail readable long after disclosure, so viewing an email can keep handing over account data, directory data, and session access after the fix is out. That makes old mailboxes part of the incident, not just the server.
CISA and partner agencies say Laundry Bear kept using CVE-2025-66376 after Zimbra patched it, against government and commercial targets across defense, education, energy, legal, media, technology, and other critical sectors. The same advisory says the exploit fires when a malicious email is rendered in Zimbra’s Classic UI, so no click is needed, and the group has used the access to take recent mail, addresses, passwords, 2FA tokens, and new app passcodes.
A separate UAC-0099 Notepad++ plugin campaign is bundled in the reporting, but it is a different triage path. The Zimbra story is the one that changes the threat model: patching the server does not undo mailbox exposure, and stolen session material can keep the compromise alive.
13 sources · Jul 24
NVD KEV
Known exploited · CISA KEV
CVSS 7.2 HIGH: zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style… EPSS 20% (97th percentile).
CISA federal remediation date Apr 1 · date passed
Timeline Sources Jul 24 Help Net Security
Russian hackers exploit unpatched Zimbra servers to steal emails - Help Net Security
Laundry Bear exploited a Zimbra Collaboration Suite vulnerability in phishing attacks targeting governments and critical sectors worldwide.
original Jul 24 The Hacker News
Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
CERT-UA links UAC-0099 to a fake Notepad++ plugin that deploys BURNYBEAR and MATCHBOIL.V2, with persistence running every three minutes on Windows.
original Jul 24 Risky Biz News
Risky Bulletin: Western cyber agencies warn of Russian hacks of Zimbra servers
A Russian hacking campaign targets Zimbra servers, the US accuses Moonshot AI of distillation attacks, Iran targets more PLC vendors, and [Read More
original Part of the PlainSec briefing for 2026-07-23
Every edition of this story: Zimbra Patches Linger While Mailboxes Stay Readable
More from today
Vulnerabilities & Exploits
Zimbra Patches Linger While Mailboxes Stay Readable The break is not the XSS alone. It is that patched Zimbra servers still left mail readable long after disclosure, so viewing an email can keep handing over account data, directory data, and session access after the fix is out. That makes old mailboxes part of the incident, not just the server.
CISA and partner agencies say Laundry Bear kept using CVE-2025-66376 after Zimbra patched it, against government and commercial targets across defense, education, energy, legal, media, technology, and other critical sectors. The same advisory says the exploit fires when a malicious email is rendered in Zimbra’s Classic UI, so no click is needed, and the group has used the access to take recent mail, addresses, passwords, 2FA tokens, and new app passcodes.
A separate UAC-0099 Notepad++ plugin campaign is bundled in the reporting, but it is a different triage path. The Zimbra story is the one that changes the threat model: patching the server does not undo mailbox exposure, and stolen session material can keep the compromise alive.
13 sources · Jul 24
NVD KEV
Known exploited · CISA KEV
CVSS 7.2 HIGH: zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style… EPSS 20% (97th percentile).
CISA federal remediation date Apr 1 · date passed
Timeline Sources Jul 24 Help Net Security
Russian hackers exploit unpatched Zimbra servers to steal emails - Help Net Security
Laundry Bear exploited a Zimbra Collaboration Suite vulnerability in phishing attacks targeting governments and critical sectors worldwide.
original Jul 24 The Hacker News
Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
CERT-UA links UAC-0099 to a fake Notepad++ plugin that deploys BURNYBEAR and MATCHBOIL.V2, with persistence running every three minutes on Windows.
original Jul 24 Risky Biz News
Risky Bulletin: Western cyber agencies warn of Russian hacks of Zimbra servers
A Russian hacking campaign targets Zimbra servers, the US accuses Moonshot AI of distillation attacks, Iran targets more PLC vendors, and [Read More
original Part of the PlainSec briefing for 2026-07-23
Every edition of this story: Zimbra Patches Linger While Mailboxes Stay Readable
More from today