CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Risky Bulletin: Western cyber agencies warn of Russian hacks of Zimbra servers

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3142

As cited

Copy frozen at (site build).

vulnerabilities

Risky Bulletin: Western cyber agencies warn of Russian hacks of Zimbra servers

Western cybersecurity and intelligence agencies issued a joint warning on Thursday about a Russian hacking campaign targeting Zimbra email servers since at least July 2024. The campaign exploited CVE-2025-66376, a stored XSS vulnerability in the Zimbra webmail client's CSS @import feature, which was patched in November but remains under active attack. The malicious code loads a tool called Ulej to harvest credentials, session tokens, backup two-factor authentication codes, saved passwords, and up to 90 days of email contents.

Why it matters: Organizations running Zimbra email servers are under active targeting by a Russian threat actor; apply the November patch immediately if not already deployed, and hunt for indicators of the Ulej tool in webmail logs.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Risky Bulletin: Western cyber agencies warn of Russian hacks of Zimbra servers

Western cybersecurity and intelligence agencies issued a joint warning about a Russian hacking campaign targeting Zimbra email servers since at least July 2025. The attacks exploit CVE-2025-66376, a stored cross-site scripting vulnerability in the webmail client's CSS @import feature, patched in November 2025. The vulnerability enables attackers to inject malicious code that deploys a credential-harvesting tool called Ulej to steal login credentials, session tokens, two-factor authentication backup codes, saved passwords, and up to 90 days of email content.

Why it matters: Organizations running Zimbra email servers face credential theft and email compromise if they have not patched CVE-2025-66376; verify the November 2025 patch is deployed and review mailbox access logs for suspicious activity.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Risky Bulletin: Western cyber agencies warn of Russian hacks of Zimbra servers

Western cybersecurity and intelligence agencies issued a joint warning about a Russian hacking campaign targeting Zimbra email servers since at least July 2025. The attacks exploit CVE-2025-66376, a stored cross-site scripting vulnerability in the webmail client's CSS @import feature, patched in November 2025. The vulnerability enables attackers to inject malicious code that deploys a credential-harvesting tool called Ulej to steal login credentials, session tokens, two-factor authentication backup codes, saved passwords, and up to 90 days of email content.

Why it matters: Organizations running Zimbra email servers face credential theft and email compromise if they have not patched CVE-2025-66376; verify the November 2025 patch is deployed and review mailbox access logs for suspicious activity.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary