#zimbra


Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets

Sep 30, 2026 // 19:50

Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according to findings from […]

Hackers breached over 270 Zimbra servers in ongoing attacks

Aug 25, 2026 // 15:16

Threat actors have already compromised over 270 Zimbra instances in remote code execution attacks targeting a high-severity Zimbra Collaboration Suite (ZCS) vulnerability. The ZCS email […]

CISA orders urgent patching of actively exploited Zimbra flaw

Aug 24, 2026 // 13:56

The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies to patch an actively exploited vulnerability in Zimbra Collaboration Suite (ZCS) within three […]

Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution

Aug 20, 2026 // 16:26

A now-patched security flaw impacting Zimbra Collaboration (ZCS) has come under active exploitation in the wild, according to the Polish Computer Emergency Response Team (CERT […]

Critical Zimbra RCE flaw now actively exploited in attacks

Aug 20, 2026 // 12:57

CERT Polska, the Polish Computer Emergency Response Team (CERT), warned that attackers have begun exploiting a critical vulnerability in Zimbra Collaboration Suite (ZCS). ZCS is […]

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

Jul 24, 2026 // 01:00

A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra’s webmail client. The payload goes after the last 90 […]

Russian hackers exploit Zimbra zero-click flaw for email theft

Jul 23, 2026 // 19:56

CISA is warning that the Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is targeting organizations using Zimbra Collaboration email servers by […]

Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities

Jul 21, 2026 // 16:21

Zimbra has rolled out fixes to address multiple critical security issues, including a command injection flaw in the Simple Network Management Protocol (SNMP) monitoring component. […]

Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions

Jul 12, 2026 // 15:38

Zimbra is urging customers to apply updates to address a critical security vulnerability impacting the Classic Web Client that could result in arbitrary code execution. […]

Zimbra urges customers to patch critical web client XSS flaw

Jul 10, 2026 // 16:56

The Zimbra security team urged customers to patch a critical vulnerability affecting the Classic Web Client used to access the Zimbra Collaboration suite. Zimbra is […]

1 2 Next