On July 23, 2026, the NSA, FBI, CISA, and 16 partner nations issued a joint advisory warning that Russian state backed group LAUNDRY BEAR exploited CVE 2025 66376, a zero click stored XSS in Zimbra Collaboration Suite... The vulnerability affected Zimbra Collaboration Suite 10.0.x before 10.0.18 and 10.1.x before 10...

Create a landscape editorial hero image for this Studio Global article: Search & fact-check with cited sources for What is the joint advisory issued by U.S. and allied cybersecurity agencies in July 2025 warning. Article summary: All key facts are confirmed from the primary advisory source and authoritative reporting. Here is the full fact-checked summary.. Topic tags: general, government, general web, user generated, education. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers, clickbait thumbnails, icons, and tiny thumbnail layouts. M
On July 23, 2026, the U.S. National Security Agency (NSA), Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and a coalition of international partners released a joint Cybersecurity Advisory titled "Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite" (TLP:CLEAR, Ver 1.0) . The advisory was co-sealed by agencies from 16 countries including the U.S., Netherlands, Australia, Canada, New Zealand, the UK, Czech Republic, Denmark, Estonia, Finland, France, Italy, Moldova, Poland, Spain, and Sweden
.
The Russian state-backed APT group is tracked as LAUNDRY BEAR, a name initially coined by the Netherlands AIVD and MIVD . The threat activity has been ongoing since at least July 2025
. The group's targeting is assessed as espionage for the Russian Federation, with "extensive Ukrainian targeting, prior to use against U.S. and other NATO allies" — Ukraine was used as a "testbench for malicious cyber techniques before broader global deployment"
. Compromised sectors include defense, education, energy, law enforcement, media, finance, transportation, and technology
.
CVE-2025-66376 is a stored cross-site scripting (XSS) vulnerability in the Zimbra Collaboration Suite (ZCS) Classic UI, caused by abuse of CSS @import directives in HTML email messages . It affects ZCS 10.0.x before 10.0.18 and 10.1.x before 10.1.13
. The vulnerability was patched by Zimbra in November 2025
. The CVSS score is reported as 7.2 (High) by some sources
or 6.1 (Medium) by others
. CISA added it to its Known Exploited Vulnerabilities Catalog in March 2026
.
This is a zero-click / view-based exploit: no user interaction beyond opening (viewing) a malicious email is required — no clicking links or opening attachments . Once triggered, a custom JavaScript payload is delivered to the victim's browser via the stored XSS
.
The group's custom data exfiltration and aggregation capability is called "beehive" . Officials warned the group could likely adapt and reuse this capability to exploit other vulnerabilities
. The advisory details a multi-stage exfiltration architecture using both HTTPS and DNS tunneling (via a tool called "Ulej" with a "Flowerbed" server component), with DNS queries structured per RFC 1035 and base32-encoded payloads
.
The advisory urges organizations to :
The vulnerability was exploited as a zero-day for about five months (July–November 2025) before patches were released, and the group continues to actively exploit unpatched instances . The advisory assesses the activity as "almost certainly" Russian state-backed espionage — no financial extortion motive was ever observed
.
Studio Global AI
Use this topic as a starting point for a fresh source-backed answer, then compare citations before you share it.
On July 23, 2026, the NSA, FBI, CISA, and 16 partner nations issued a joint advisory warning that Russian state backed group LAUNDRY BEAR exploited CVE 2025 66376, a zero click stored XSS in Zimbra Collaboration Suite...
On July 23, 2026, the NSA, FBI, CISA, and 16 partner nations issued a joint advisory warning that Russian state backed group LAUNDRY BEAR exploited CVE 2025 66376, a zero click stored XSS in Zimbra Collaboration Suite... The vulnerability affected Zimbra Collaboration Suite 10.0.x before 10.0.18 and 10.1.x before 10.1.13, was patched in November 2025, and continues to be actively exploited against unpatched instances.
Organizations are urged to patch immediately, switch to the Modern UI, and monitor for indicators of compromise (IOCs) provided in the advisory.