
Zimbra Collaboration Suite
Zimbra Collaboration Suite (ZCS) is an open-source email and collaboration platform used by organisations as a self-hosted webmail alternative.
Last refreshed: 24 July 2026 · Appears in 1 active topic
Zimbra patched this flaw in November 2025, so why was it still handing hackers whole inboxes eight months later?
Timeline for Zimbra Collaboration Suite
Zimbra preview leaks mail to Russia
Cybersecurity: Threats and DefencesBackground
Zimbra Collaboration Suite (ZCS) is the webmail platform LAUNDRY BEAR used for a zero-click exploit disclosed in a 15-agency advisory on 23 July 2026. Merely previewing one email exfiltrates 90 days of mail and the organisation's Global Address List, with no user action required.
ZCS is an open-source email and collaboration platform organisations run as a self-hosted alternative to commercial webmail. The exploited flaw, CVE-2025-66376, was patched by Zimbra in November 2025, meaning any appliance still exposed in July 2026 had gone eight months without the fix.
The advisory warns LAUNDRY BEAR is likely to pivot to other webmail platforms once ZCS patching climbs, so closing this specific vulnerability addresses today's exposure rather than the group's underlying capability.