Skip to content

Russian Attackers Exploit Zero-Click Vulnerability in Zimbra Against Western Authorities

Bottom line: Zero-click vulnerability in Zimbra is being exploited by Russian attackers against western authorities since July 2025.

Since July 2025, western government agencies and state institutions have been compromised through a zero-click vulnerability in Zimbra collaboration software. The attacks are attributed to Russian actors.

Since July 2025, Russian attackers have been leveraging a zero-click vulnerability in Zimbra collaboration software to infiltrate systems at western governments and state institutions. In zero-click exploits, compromise occurs without user interaction – emails or attachments do not need to be opened.

For CISOs, this type of attack presents a significant challenge: Zimbra is frequently deployed as a mail and groupware solution in government agencies. Uncontrolled exploitability without requiring user action means that traditional security awareness training (phishing awareness) is ineffective in this case. All systems running vulnerable Zimbra versions are automatically exposed.

An immediate inventory of Zimbra infrastructure is necessary. Vendors and agency networks should be checked for available patches and mitigations. Should no patch be available, isolation or network segmentation measures should be considered. Additionally, logs should be reviewed for signs of compromise – particularly unusual mail access and forwarding.


Source: www.heise.de · Published July 24, 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: