- 
                        Critical Zimbra SSRF Flaw Exposes Sensitive Data
                        18 Oct 2025 13:48 GMT
                        
                           … SSRF vulnerability discovered in Zimbra’s chat proxy configuration …  data stored within the Zimbra environment.
                          Network Reconnaissance:  …  to systems.
                          However, Zimbra has classified the deployment  … to exploitation, particularly given Zimbra’s widespread use in  …
                         
- 
                        Critical Zimbra SSRF Vulnerability Let Attackers Access Sensitive Data
                        18 Oct 2025 09:00 GMT
                        
                           …  Forgery (SSRF) flaw in Zimbra Collaboration Suite has raised major …  user data.
                          According to Zimbra’s latest advisory, this  … who rely on Zimbra for email and collaboration.
                          Zimbra has released  …  threat but also enhances Zimbra’s overall resilience and  …
                         
- 
                        CISA Warns of Zimbra Collaboration Suite (ZCS) XSS Zero-Day Vulnerability Actively Exploited in Attacks
                        08 Oct 2025 12:08 GMT
                        
                           … popular email and collaboration platform.
                          Zimbra Collaboration Suite (ZCS) XSS Flaw … requires immediate attention from all Zimbra Collaboration Suite administrators. 
                          Security teams …  should monitor the official Zimbra Security Center and National  …
                         
- 
                        CISA Alerts on Zimbra Collaboration Suite Zero-Day XSS Flaw Exploited in Ongoing Attacks
                        08 Oct 2025 11:58 GMT
                        
                           …  scripting (XSS) flaw in the Zimbra Collaboration Suite (ZCS).
                          This vulnerability … .
                          Product
                          CVE ID
                          Vulnerability Description
                          Zimbra Collaboration Suite (ZCS)
                          CVE-2025 …  affects all supported versions of Zimbra Collaboration Suite that include the …
                         
- 
                        U.S. CISA adds Synacor Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalog
                        07 Oct 2025 23:47 GMT
                        
                           … Security Agency (CISA) adds Synacor Zimbra Collaboration Suite (ZCS) flaw to …  Security Agency (CISA) added Synacor Zimbra Collaboration Suite (ZCS) flaw, tracked …  JavaScript.
                          The malicious script targets Zimbra Webmail, stealing credentials, emails, contacts …
                         
- 
                        Zimbra users targeted in zero-day exploit using iCalendar attachments
                        06 Oct 2025 20:24 GMT
                        
                           … 
                          Threat actors exploited a Zimbra zero-day via malicious  …  CVE-2025-27915 in Zimbra Collaboration Suite in zero- … JavaScript.
                          The malicious script targets Zimbra Webmail, stealing credentials, emails, … data theft.
                          Queries the Zimbra SOAP API to enumerate  …
                         
- 
                        Zimbra Zero-Day Exploited to Target Brazilian Military via Malicious ICS Files
                        06 Oct 2025 15:27 GMT
                        
                           …  patched security vulnerability in Zimbra Collaboration was exploited as … vulnerability was addressed by Zimbra as part of versions  … folder, and adds malicious Zimbra email filter rules with … Roundcube, Horde, MDaemon, and Zimbra to obtain unauthorized access.
                           …
                         
- 
                        Hackers Exploit Zimbra Vulnerability as 0-Day with Weaponized iCalendar Files
                        06 Oct 2025 08:07 GMT
                        
                           … day vulnerability in the Zimbra Collaboration Suite (ZCS) was … the issue lies within Zimbra’s Classic Web Client, … the user’s knowledge.
                          Zimbra addressed the vulnerability on  … data stealer designed specifically for Zimbra webmail. Its capabilities include …
                         
- 
                        SideWinder Hacker Group Targets Users with Fake Outlook/Zimbra Portals to Steal Login Credentials
                        03 Oct 2025 17:58 GMT
                        
                           …  fake Outlook Web App and Zimbra webmail login pages.
                          The group …  has been targeted through fake Zimbra portals, with stolen credentials funneled …
                         
- 
                        SideWinder Hacker Group Hosting Fake Outlook/Zimbra Portals to Steal Login Credentials
                        03 Oct 2025 16:50 GMT
                        
                           …  that mimic legitimate Outlook and Zimbra webmail services.
                          Emerging in mid …