Zimbra Behind a Reverse Proxy: Finding Mail Servers That Refuse to Identify Themselves
CISA advisory AA26-204A, published 23 July 2026, describes a Russian state-supported group tracked primarily as LAUNDRY BEAR compromising Zimbra Collaboration Suite deployments. The exploitation path uses CVE-2025-66376, an improper sanitization issue in CSS @import directives that executes a JavaScript payload when a malicious email is viewed. According to the advisory, the actors exfiltrated the previous 90 days of email, the Global Address List, two-factor authentication tokens and application passcodes.
The advisory states the actors located public-facing Zimbra infrastructure through port scanning and commercial fingerprinting datasets. That is exactly the problem a well-configured reverse proxy is supposed to solve, and the ZoomEye data suggests it only partially does.
What a proxy changes about discoverability
Global queries captured on 25 September 2026 show the scale of the problem and the shape of the workaround.
The application fingerprint, app="Zimbra", returns 210,812 assets. The strict product title, title="Zimbra Collaboration Suite", returns 3,661, and adding the encrypted web port, title="Zimbra Collaboration Suite" && port="443", returns 265.
Now consider the proxy signal. http.header.server="nginx" && title="Zimbra Collaboration Suite" returns 841 assets, more than three times the number returned by the same title restricted to port 443. Assets whose title names the product are more likely to be found behind a proxy header than behind the encrypted port filter, which tells the defender that the front end is doing more of the talking than the application is.
Why the certificate layer still works
A reverse proxy can rewrite headers, normalize responses and hide the application's own banners. It cannot hide the certificate, because the certificate is presented during the TLS handshake before any HTTP conversation begins.
That is why ssl="Zimbra" && title="Zimbra" returns 63,239 assets. Where an operator has published a certificate referencing the product and also left the product name in a page title, two independent disclosures point at the same host. This intersection is the most reliable external indicator of a genuine deployment that the data set offers.
It is also a reminder that the proxy is not the only layer a defender controls. Hostname naming, certificate subject fields and the presence or absence of a product token in a title are editorial decisions with external consequences.
A discovery method that assumes the front end lies
For an organization that suspects it has forgotten deployments, assume the front end will not identify the application and work backwards.
Query the proxy header together with the product title to find assets that admit to the proxy but still reveal the product. Query the certificate intersection to find hosts that published the product name at the TLS layer. Query the bare fingerprint for hosts that reveal the product in protocol banners instead of pages. The three result sets overlap imperfectly, and the differences between them are the finding.
Then apply the same logic to the mail path. A bare port="7071" query returns 2,506,465 assets and is useless on its own, but app="Zimbra" && port="7071" returns 161 assets, a small set of administrative interfaces that are precisely the assets a proxy configuration is least likely to have been reviewed for.
What this method cannot do
None of these queries report patch level, and none of them indicate that a specific host was targeted or compromised. The advisory lists targets across the defense industrial base, government, education, energy, law enforcement, media, non-governmental organizations and technology, and it notes that even organizations with mature cybersecurity processes should validate external connections, including cellular modems that may not appear in routine scans.
External discovery answers where to look. Confirming whether the mailbox was accessed requires the host's own logs and the indicators of compromise published with the advisory.
A note on scope. All counts were captured on 25 September 2026 with global ZoomEye queries and describe internet-visible assets. Exposure is not exploitation.
References
- CISA, AA26-204A, Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite, 23 July 2026: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a
- National Vulnerability Database, CVE-2025-66376: https://nvd.nist.gov/vuln/detail/CVE-2025-66376
- ZoomEye cyberspace search, global query counts captured 25 September 2026: https://www.zoomeye.ai/
Top comments (0)