Tag

Zimbra

All articles tagged with #zimbra

CISA orders rapid patch for actively exploited Zimbra flaw
security5 days ago

CISA orders rapid patch for actively exploited Zimbra flaw

CISA has ordered U.S. federal agencies to patch CVE-2026-73570 in Zimbra Collaboration Suite within three days after the flaw was actively exploited, enabling unauthenticated remote code execution via a SNMP command-injection vulnerability when SNMP notifications are enabled. Zimbra patched the vulnerability in version 10.1.20 (July 20). CERT Polska flagged exploitation in the wild; Shadowserver reports thousands of exposed Zimbra servers and hundreds of compromised instances. Authorities urge checking logs for suspicious activity and for files created by the zimbra user in /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps, and /tmp over the past month. Given ZCS’s widespread use, governments and businesses remain at risk, with past campaigns tied to APT groups exploiting Zimbra flaws.

Zimbra RCE Flaw CVE-2026-73570 Actively Exploited in the Wild
technology8 days ago

Zimbra RCE Flaw CVE-2026-73570 Actively Exploited in the Wild

Polish CERT Polska reports active exploitation of CVE-2026-73570 in Zimbra Collaboration Suite, a SNMP-related command-injection remote-code-execution flaw. Zimbra patched it in 10.1.20 (July 20). Unauthenticated attackers can trigger OS commands via crafted SMTP requests when SNMP is enabled. Shadowserver lists over 12,000 exposed Zimbra servers, mainly in Europe and Asia; admins should check logs for anomalies and update to the patched release.

Russian Spy Group Exploits Zimbra Zero-Day to Steal Mail, Passwords and 2FA Codes
technology1 month ago

Russian Spy Group Exploits Zimbra Zero-Day to Steal Mail, Passwords and 2FA Codes

A Russian state-backed espionage group exploited a stored cross-site scripting flaw in Zimbra's Classic UI (CVE-2025-66376) to automatically render a malicious email in an authenticated webmail session, stealing CSRF tokens, browser-saved passwords, and 2FA scratch codes, and exfiltrating 90 days of mail; patching the vulnerability is necessary but does not revoke credentials, so organizations should patch, reset passwords, invalidate sessions, review for the ZimbraWeb app-specific password, and monitor for identified indicators of compromise.

Global Governments Targeted in Massive Zimbra Zero-Day Hacking Spree
cybersecurity2 years ago

Global Governments Targeted in Massive Zimbra Zero-Day Hacking Spree

Google's Threat Analysis Group (TAG) has discovered that hackers exploited a zero-day vulnerability in Zimbra Collaboration email server, known as CVE-2023-37580, to steal sensitive data from government systems in multiple countries. The vulnerability, an XSS issue in the Zimbra Classic Web Client, was exploited by four distinct threat actors before the vendor released a patch. The attacks involved email data exfiltration, auto-forwarding, and phishing. Google's report highlights the importance of timely security updates, even for medium-severity vulnerabilities, as adversaries can exploit them to further their attacks. This incident is another example of XSS flaws being leveraged to target mail servers.

Global Government Data Breach: Zimbra Zero-Day Exploited by Multiple Hacker Groups
vulnerability-email-security2 years ago

Global Government Data Breach: Zimbra Zero-Day Exploited by Multiple Hacker Groups

Four hacker groups have exploited a zero-day flaw in the Zimbra Collaboration email software, allowing them to steal email data, user credentials, and authentication tokens. The vulnerability, tracked as CVE-2023-37580, is a reflected cross-site scripting (XSS) flaw that was addressed by Zimbra in July 2023. The attacks occurred even after the initial fix was made public on GitHub, highlighting the importance of promptly applying patches to mail servers. The campaigns targeted government organizations in Greece, Moldova, Tunisia, and Vietnam, demonstrating the need for thorough auditing of mail server applications.