A significant cybersecurity breach has come to light involving a Russian state-supported espionage group that exploited a previously unknown vulnerability in Zimbra's webmail client. This breach allowed the group to access and read emails from Western government and commercial organizations for several months. The vulnerability, tracked as CVE-2025-66376, is a stored cross-site scripting flaw in Zimbra's Classic UI. It allows attackers to execute malicious JavaScript when a user views a crafted HTML email, effectively granting unauthorized access to the user's mailbox.

The National Security Agency, Cybersecurity and Infrastructure Security Agency, and partner agencies have issued a joint advisory on this exploitation, supported by research from Palo Alto Networks' Unit 42 and Proofpoint. The flaw has been actively targeted since at least July 2025 and affects Zimbra Collaboration versions 10.0 before 10.0.18 and 10.1 before 10.1.13. Zimbra addressed the vulnerability with a patch released on November 6, 2025, which was later added to the Known Exploited Vulnerabilities catalog by CISA in March 2026.

Proofpoint identified the espionage group as TA488, noting that the actors used Proton Mail accounts and previously compromised addresses to distribute the exploit. The malicious emails often appeared as a news digest to lure recipients. The exploit, known as ZimReaper, captures sensitive information such as CSRF tokens, autofilled passwords, and two-factor authentication codes. It also exfiltrates data over DNS queries to the attackers' infrastructure.

The advisory highlights the ongoing threat posed by this group, which continues to target unpatched Zimbra instances. While Proofpoint has not observed activity from TA488 since February 2026, organizations are urged to update their systems to the latest patch levels and review user accounts for potential compromise. Ensuring that all email systems are patched and secure is critical to preventing further exploitation.