What is CVE-2025-66376?
Threat actor TA488 exploited a previously unknown vulnerability in Zimbra mail servers for five months, enabling remote code execution. This critical flaw impacts exposed Zimbra instances, risking full system compromise. Affected organizations must urgently apply security patches and inspect systems for compromise indicators.
Azərbaycanca: Təhlükə aktoru TA488 beş ay ərzində Zimbra mail serverlərində əvvəllər məlum olmayan boşluqdan istifadə edərək hədəflənmiş hücumlar həyata keçirib. Bu kritik boşluq uzaqdan kod icrasına imkan verir, təsirlənən Zimbra qurğularını tam ələ keçirmə riski yaradır. Zərərçəkənlər dərhal təhlükəsizlik yamalarını tətbiq etməli və güzəşt göstəriciləri üçün sistemləri yoxlamalıdır.
Related CVEs
link basis: shared threat actors: Laundry Bear, TA488, Void Blizzard; shared vendor: Proofpoint
FAQ2
Which threat actor exploited CVE-2025-66376?
The threat actor TA488 exploited this vulnerability.
What is the impact of CVE-2025-66376 on Zimbra mail servers?
This critical flaw enables remote code execution (RCE), risking full compromise of the affected instances.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.