Vulnerabilities & Exploits

Zimbra Patches Linger While Mailboxes Stay Readable

The break is not the XSS alone. It is that patched Zimbra servers still left mail readable long after disclosure, so viewing an email can keep handing over account data, directory data, and session access after the fix is out. That makes old mailboxes part of the incident, not just the server.

CISA and partner agencies say Laundry Bear kept using CVE-2025-66376 after Zimbra patched it, against government and commercial targets across defense, education, energy, legal, media, technology, and other critical sectors. The same advisory says the exploit fires when a malicious email is rendered in Zimbra’s Classic UI, so no click is needed, and the group has used the access to take recent mail, addresses, passwords, 2FA tokens, and new app passcodes.

A separate UAC-0099 Notepad++ plugin campaign is bundled in the reporting, but it is a different triage path. The Zimbra story is the one that changes the threat model: patching the server does not undo mailbox exposure, and stolen session material can keep the compromise alive.

13 sources · Jul 24

CVE-2025-66376

NVD KEV

Known exploited · CISA KEV

CVSS 7.2 HIGH: zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style… EPSS 20% (97th percentile).

CISA federal remediation date Apr 1 · date passed

Timeline

Sources

Part of the PlainSec briefing for 2026-07-23

Every edition of this story: Zimbra Patches Linger While Mailboxes Stay Readable

More from today