-
Critical Zimbra SSRF Vulnerability Let Attackers Access Sensitive Data
18 Oct 2025 09:00 GMT
… Forgery (SSRF) flaw in Zimbra Collaboration Suite has raised major … user data.
According to Zimbra’s latest advisory, this … who rely on Zimbra for email and collaboration.
Zimbra has released … threat but also enhances Zimbra’s overall resilience and …
-
CISA Alerts on Zimbra Collaboration Suite Zero-Day XSS Flaw Exploited in Ongoing Attacks
08 Oct 2025 11:58 GMT
… scripting (XSS) flaw in the Zimbra Collaboration Suite (ZCS).
This vulnerability … .
Product
CVE ID
Vulnerability Description
Zimbra Collaboration Suite (ZCS)
CVE-2025 … affects all supported versions of Zimbra Collaboration Suite that include the …
-
Zimbra Zero-Day Exploited to Target Brazilian Military via Malicious ICS Files
06 Oct 2025 15:27 GMT
… patched security vulnerability in Zimbra Collaboration was exploited as … vulnerability was addressed by Zimbra as part of versions … folder, and adds malicious Zimbra email filter rules with … Roundcube, Horde, MDaemon, and Zimbra to obtain unauthorized access.
…
-
Hackers Exploit Zimbra Vulnerability as 0-Day with Weaponized iCalendar Files
06 Oct 2025 08:07 GMT
… day vulnerability in the Zimbra Collaboration Suite (ZCS) was … the issue lies within Zimbra’s Classic Web Client, … the user’s knowledge.
Zimbra addressed the vulnerability on … data stealer designed specifically for Zimbra webmail. Its capabilities include …
-
SideWinder Hacker Group Targets Users with Fake Outlook/Zimbra Portals to Steal Login Credentials
03 Oct 2025 17:58 GMT
… fake Outlook Web App and Zimbra webmail login pages.
The group … has been targeted through fake Zimbra portals, with stolen credentials funneled …
-
SideWinder Hacker Group Hosting Fake Outlook/Zimbra Portals to Steal Login Credentials
03 Oct 2025 16:50 GMT
… that mimic legitimate Outlook and Zimbra webmail services.
Emerging in mid …
-
U.S. CISA adds MRLG, PHPMailer, Rails Ruby on Rails, and Synacor Zimbra Collaboration Suite flaws to its Known Exploited Vulnerabilities catalog
09 Jul 2025 01:37 GMT
… on Rails, and Synacor Zimbra Collaboration Suite (ZCS) flaws … on Rails, and Synacor Zimbra Collaboration Suite (ZCS) flaws … score: 7.5) Synacor Zimbra Collaboration Suite (ZCS) Server- … -2019-9621 vulnerability impacts Zimbra Collaboration Suite before 8.6 …
-
CISA Issues Alert Over Actively Exploited Flaw in Zimbra Collaboration Suite
08 Jul 2025 06:57 GMT
… exploited vulnerability in Synacor’s Zimbra Collaboration Suite (ZCS), urging … vulnerability impacts multiple versions of Zimbra Collaboration Suite, including:
ZCS … issued patches and mitigations for Zimbra Collaboration Suite immediately.
Follow BOD …
-
Zimbra Classic Web Client Vulnerability Let Attackers Execute Arbitrary JavaScript
24 Jun 2025 19:03 GMT
… risks to organizations using affected Zimbra installations, prompting immediate patch deployment … execution
Exploit Prerequisites
Access to Zimbra Classic Web Client interface, … script injection.
The following Zimbra versions have received critical security …
-
Zimbra Classic Web Client Vulnerability Allows Arbitrary JavaScript Execution
24 Jun 2025 19:03 GMT
… The vulnerability impacts the following Zimbra Collaboration Suite versions:
9. … JavaScript execution.
Mitigation and Recommendations
Zimbra administrators should immediately upgrade to … critical flaws recently addressed in Zimbra, including SQL injection and …