Find notable cyber news and cases, enriched with sources, timelines, and signals.
Vulnerability Advisory/Mitigation Campaign

APT28 GhostMail abuse of Zimbra Classic UI flaw

Updated 19.03.2026 16:55
Case score 65
Members 3 First seen 18.03.2026 21:57 Latest activity 19.03.2026 16:55

Overview

**CVE-2025-66376** in **Zimbra Collaboration Suite (ZCS)** is being used in active attacks that abuse the Classic UI and email-delivered CSS `@import` content to run stored XSS in a victim session. **APT28**'s Operation GhostMail applies that path against Ukrainian government entities and can pull credentials, session tokens, and mailbox data. **CISA** has already added the flaw to the exploited-in-the-wild catalog and ordered Federal Civilian Executive Branch agencies to secure affected servers by **April 1, 2026**. Synacor patched the issue in early November, but the available evidence does not quantify how broad the exploitation is.
Latest development Open development history 3 earlier developments CISA orders agencies to patch actively exploited Zimbra CVE-2025-66376 CISA ordered U.S. Federal Civilian Executive Branch agencies to secure Zimbra Collaboration Suite (ZCS) servers against CVE-2025-66376, a stored cross-site scripting flaw in the Classic UI that attackers can trigger through CSS @import directives in email HTML. The agency said the vulnerability was actively exploited in the wild, gave federal agencies two weeks to comply by April 1, 2026 under BOD 22-01, and urged all organizations to apply vendor mitigations or discontinue use if mitigations are unavailable. The flaw had been patched in early November and could enable arbitrary JavaScript execution, user-session hijacking, and sensitive-data theft within affected Zimbra environments.
  1. Earlier development

    APT28 Operation GhostMail targets Ukrainian government entities

    APT28, a Russia-linked GRU threat group, is exploiting CVE-2025-66376 in Zimbra Collaboration Suite (ZCS) against Ukrainian government entities through a phishing campaign called Operation GhostMail. The messages deliver an obfuscated JavaScript payload in the HTML body of a single email, and one named target is the Ukrainian State Hydrology Agency.

  2. Earlier development

    Interlock exploits Cisco firewall zero-day for initial access

    Threat actors associated with Interlock ransomware have exploited Cisco's firewall management software CVE-2026-20131 as a zero-day since January 26, 2026, using the edge-device flaw to gain initial access to target networks and showing a continuing focus on perimeter devices.

  3. Earlier development

    CISA urges FCEB patching for Zimbra and SharePoint flaws

    CISA urged Federal Civilian Executive Branch (FCEB) agencies to apply patches for CVE-2025-66376 in Synacor Zimbra Collaboration Suite (ZCS) by April 1, 2026 and CVE-2026-20963 in Microsoft Office SharePoint by March 23, 2026 after identifying both flaws as actively exploited in the wild.

Signals

Impact signals
Exploitation
CVEs/products
Geographic context
Remediation
Status
Threat context

Threat actor context

3 listed

Malware context

1 families

Technical intelligence

Existing Case data

Member happenings

Vulnerability Zimbra Collaboration Suite (ZCS) stored XSS flaw (CVE-2025-66376)
Updated 18.03.2026 21:57 Lead Contribution 62
Exploitation Active Exploitation Exploit No Known Public Exploit Data Type Email Addresses CVSS 10.0 Critical 1 more in details
All signals
Exploitation Active Exploitation Exploit No Known Public Exploit Data Type Email Addresses CVSS 10.0 Critical Patch Patch Available

**CVE-2025-66376** affects **Zimbra Collaboration Suite (ZCS)**, where a stored **XSS flaw** in the **Classic UI** is **actively exploited** and can put exposed mail servers and user sessions at risk. Remote unauthenticated attackers can abuse **CSS @import directives** in email HTML to trigger the weakness, with potential follow-on impacts including session hijacking and sensitive-data theft. The issue was **patched in early November**, but unremediated deployments remain exposed.

Campaign APT28 Operation GhostMail Zimbra phishing campaign targeting Ukrainian government entities
Updated 19.03.2026 16:55 Scoring Support Contribution 2
Objective Espionage Campaign Active Patch Patch Available

**APT28**’s **Operation GhostMail** is actively targeting **Ukrainian government entities** through a phishing chain that exploits **CVE-2025-66376** in **Zimbra Collaboration Suite**, creating immediate risk to email accounts and credentials. The message delivers an obfuscated **JavaScript** payload in the **HTML body** of a single email, avoiding attachments and macros. The payload can harvest **session tokens**, backup **2FA codes**, browser-saved passwords, and mailbox content from the last **90 days**. The activity matters because the vulnerability is already treated as exploited in the wild, and one named target is the **Ukrainian State Hydrology Agency**, a critical infrastructure entity.

Advisory/Mitigation CISA patch guidance for Zimbra and SharePoint flaws
Updated 19.03.2026 08:05 Context
Exploitation Active Exploitation CVSS 10.0 Critical Urgency High Patch Patch Available

**CISA** told **FCEB agencies** to patch **two actively exploited vulnerabilities** in **Synacor Zimbra Collaboration Suite (ZCS)** and **Microsoft Office SharePoint**, creating immediate risk for government collaboration systems. The directive covers **CVE-2025-66376** in ZCS and **CVE-2026-20963** in SharePoint, with deadlines of **March 23, 2026** and **April 1, 2026**. Public reporting does not identify the attackers or the scale of exploitation, but both flaws are already fixed and require prompt remediation.