The Five-Month Gap: Zimbra Exposure Between Zero-Day Exploitation and Public Disclosure
The timeline in CISA advisory AA26-204A is the most useful part of it. A Russian state-supported group tracked as LAUNDRY BEAR began exploiting what became CVE-2025-66376 in Zimbra Collaboration Suite in at least July 2025, the flaw was zero-day at that point, Synacor patched it in November 2025, and the CVE was published on 5 January 2026. The advisory itself appeared on 23 July 2026, a year after the initial exploitation.
That sequence leaves defenders with a question that external measurement cannot answer directly but can frame: how much of the exposed population shows signs of having moved at all?
What changed on the patch date
CVE-2025-66376 is an improper sanitization flaw in CSS @import handling. A crafted message executes JavaScript when viewed in the Zimbra webmail client, and the exploitation does not require the victim to click anything beyond opening the message. A patch that removes the client-side execution path is the fix, and it is applied at the server.
Against that, the certificate signal is a reasonable proxy for recent administrative activity. ssl="Zimbra" && title="Zimbra" returns 63,239 assets, and the broader fingerprint, app="Zimbra", returns 210,812. The ratio is not a patch rate, and it should not be presented as one, because a certificate can be renewed without any application update and an updated application may keep an old certificate. What the comparison does report is how many deployments have at least one independently refreshed, externally visible artifact.
A time-bounded view of the same population
ZoomEye allows a query to be limited by indexing recency. app="Zimbra" && after="2026-01-01" returns 62,713 assets, which is roughly thirty percent of the full Zimbra fingerprint. Read correctly, this says that about three in ten of the indexed Zimbra assets have been observed since the start of 2026.
Read incorrectly, it says that seventy percent of Zimbra deployments are unpatched, which is not supported. Indexing recency reflects the crawler's schedule and the target's availability as much as it reflects administrative action. The correct use of the number is comparative: run the same bounded query every quarter and watch the share change, because a share that moves is a program effect and a share that is flat is a program that is not running.
Turning the gap into a checklist
The advisory documents what happened during the gap and what defenders should do about it. Applied to the exposure data, the practical list looks like this.
Confirm that every internet-reachable Zimbra front end you own is on a build released after November 2025. Compare the addresses that appear in the fingerprint results against your own inventory, since the advisory notes that even organizations with mature processes retained externally visible mail infrastructure. Review the administrative port separately, because app="Zimbra" && port="7071" returns 161 assets and an exposed management interface is a different problem from an exposed webmail client. And treat the two-factor tokens harvested in this campaign as compromised credentials rather than as a technical footnote, because the advisory states the actors collected them and used the access to establish persistence before rotating infrastructure every seven to sixty days.
Why the gap is the finding
Five months of exploitation before a patch, followed by two more months before a public CVE, is a reminder that the interval between an adversary learning a technique and a defender learning about it is measured in quarters. External exposure data occupies the wrong end of that interval by definition, since it describes the state of the internet now and not the state it was in when the campaign started.
What it can do is provide a baseline against which the next advisory is measured. The organizations that answer that well are the ones whose numbers move before they are told to move them.
Scope. All counts are global ZoomEye queries captured on 25 September 2026 and describe internet-visible assets. They do not indicate patch status, targeting or compromise.
References
- CISA, AA26-204A, Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite, 23 July 2026: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a
- National Vulnerability Database, CVE-2025-66376: https://nvd.nist.gov/vuln/detail/CVE-2025-66376
- ZoomEye cyberspace search, global query counts captured 25 September 2026: https://www.zoomeye.ai/
Top comments (0)