Tag: Zimbra


  • Zimbra RCE Flaw Actively Exploited in Attacks

    A critical Zimbra RCE flaw is now being actively exploited, prompting administrators to patch vulnerable email servers and review their systems for signs of compromise. The issue affects Zimbra Collaboration Suite installations that use SNMP notifications. Tracked as CVE-2026-73570, the vulnerability allows an unauthenticated attacker to execute operating-system commands as the Zimbra user. Attackers can…

  • Zimbra Zero-Click Flaw Used in Russian Email Theft Attacks

    Russian state-linked hackers have used a patched Zimbra zero-click flaw to steal emails, account credentials and multi-factor authentication tokens from targeted organisations. The US Cybersecurity and Infrastructure Security Agency (CISA) says the group, known as Laundry Bear or Void Blizzard, combines the Zimbra vulnerability with phishing attacks that impersonate legitimate email login portals. Zero-click Zimbra…

  • Zimbra zero-day exploit uses iCalendar files to steal emails and credentials

    A new Zimbra zero-day exploit has been used in targeted attacks worldwide. Hackers deployed malicious iCalendar files to inject JavaScript, steal credentials, and access victims’ emails. The flaw allowed remote code execution inside active webmail sessions, giving attackers full control over compromised accounts. How the Zimbra Zero-Day Exploit Worked Researchers identified the vulnerability as CVE-2025-27915,…