APT28 GhostMail abuse of Zimbra Classic UI flaw
Case score 65
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 65
- Main story score
- 62
- Related evidence lift
- +3 / 20
- Contributing updates
- 1
- Context updates
- 1
- Vulnerability Core Zimbra Classic UI stored-XSS flaw and the main exploitation surface. main
- Campaign APT28's GhostMail operation shows direct real-world abuse of the same Zimbra flaw against Ukrainian government entities. contributes
- Advisory Mitigation CISA guidance confirms the flaw is treated as exploited in the wild and sets a remediation deadline. context
Overview
Latest development Open development history CISA orders agencies to patch actively exploited Zimbra CVE-2025-66376 CISA ordered U.S. Federal Civilian Executive Branch agencies to secure Zimbra Collaboration Suite (ZCS) servers against CVE-2025-66376, a stored cross-site scripting flaw in the Classic UI that attackers can trigger through CSS @import directives in email HTML. The agency said the vulnerability was actively exploited in the wild, gave federal agencies two weeks to comply by April 1, 2026 under BOD 22-01, and urged all organizations to apply vendor mitigations or discontinue use if mitigations are unavailable. The flaw had been patched in early November and could enable arbitrary JavaScript execution, user-session hijacking, and sensitive-data theft within affected Zimbra environments.
-
APT28 Operation GhostMail targets Ukrainian government entities
APT28, a Russia-linked GRU threat group, is exploiting CVE-2025-66376 in Zimbra Collaboration Suite (ZCS) against Ukrainian government entities through a phishing campaign called Operation GhostMail. The messages deliver an obfuscated JavaScript payload in the HTML body of a single email, and one named target is the Ukrainian State Hydrology Agency.
-
Interlock exploits Cisco firewall zero-day for initial access
Threat actors associated with Interlock ransomware have exploited Cisco's firewall management software CVE-2026-20131 as a zero-day since January 26, 2026, using the edge-device flaw to gain initial access to target networks and showing a continuing focus on perimeter devices.
-
CISA urges FCEB patching for Zimbra and SharePoint flaws
CISA urged Federal Civilian Executive Branch (FCEB) agencies to apply patches for CVE-2025-66376 in Synacor Zimbra Collaboration Suite (ZCS) by April 1, 2026 and CVE-2026-20963 in Microsoft Office SharePoint by March 23, 2026 after identifying both flaws as actively exploited in the wild.