Skip to content
You can now search across every topic, entity and event.What's new
Zimbra Collaboration Suite
Product

Zimbra Collaboration Suite

Zimbra Collaboration Suite (ZCS) is an open-source email and collaboration platform used by organisations as a self-hosted webmail alternative.

Last refreshed: 24 July 2026 · Appears in 1 active topic

Key Question

Zimbra patched this flaw in November 2025, so why was it still handing hackers whole inboxes eight months later?

Timeline for Zimbra Collaboration Suite

#11 23 Jul

Zimbra preview leaks mail to Russia

Cybersecurity: Threats and Defences
View full timeline →

Background

Zimbra Collaboration Suite (ZCS) is the webmail platform LAUNDRY BEAR used for a zero-click exploit disclosed in a 15-agency advisory on 23 July 2026. Merely previewing one email exfiltrates 90 days of mail and the organisation's Global Address List, with no user action required.

ZCS is an open-source email and collaboration platform organisations run as a self-hosted alternative to commercial webmail. The exploited flaw, CVE-2025-66376, was patched by Zimbra in November 2025, meaning any appliance still exposed in July 2026 had gone eight months without the fix.

The advisory warns LAUNDRY BEAR is likely to pivot to other webmail platforms once ZCS patching climbs, so closing this specific vulnerability addresses today's exposure rather than the group's underlying capability.

Common Questions
What is Zimbra Collaboration Suite?
Zimbra Collaboration Suite (ZCS) is an open-source email and collaboration platform organisations run as a self-hosted alternative to commercial webmail.Source: CISA
Is Zimbra webmail safe to use?
Organisations that applied the November 2025 patch for CVE-2025-66376 are protected; any unpatched appliance remains exposed to LAUNDRY BEAR's zero-click exploit disclosed on 23 July 2026.Source: CISA
What happens if you preview an email in a vulnerable Zimbra inbox?
The zero-click exploit fires the moment the email is previewed, exfiltrating the last 90 days of mail and the organisation's Global Address List without any further action from the user.Source: CISA
Source Material