Zimbra Mailservers Targeted with Half-Click Exploits

Reported 23 Jul 2026 by otx · Severity: medium

Russian-aligned threat actor TA488, also known as Void Blizzard and Laundry Bear, exploited a previously unknown vulnerability in Zimbra Collaboration Suite mailservers for at least five months during 2025. The vulnerability, later assigned CVE-2025-66376, was leveraged through h