Visualização normal

Antes de ontemStream principal
  • ✇Cybersecurity News
  • CVE-2026-73570 Exploited in the Wild: Unauthenticated RCE Hits Zimbra Do Son
    CVE-2026-73570 is exploited in the wild. This unauthenticated RCE hits Zimbra Collaboration via SNMP notifications. Patch to 10.1.20 now. Related Posts: CVE-2026-47301: PoC Exploit Achieves SYSTEM-Level Code Execution in SCCM CVE-2026-66780 (CVSS 9.9): MITM Flaw Hits Red Hat ACM CVE-2026-76404: Critical Remote Code Execution Hits Splunk MCP Server App (CVSS 9.1) The post CVE-2026-73570 Exploited in the Wild: Unauthenticated RCE Hits Zimbra appeared first on Daily CyberSecurity.
     

Russian Hackers Used a Zimbra Zero-Day to Steal Emails Without Link Clicks

Russian hackers from the TA488 group exploited a Zimbra webmail flaw triggered when emails were opened or previewed, stealing credentials and up to 90 days of messages from victims.
  • ✇Security Affairs
  • Zimbra 10.1.20 patches multiple security issues, including a critical command injection bug Pierluigi Paganini
    Zimbra patched nine flaws in version 10.1.20, including a critical SNMP monitoring command injection issue enabling arbitrary command execution. Zimbra released version 10.1.20 to fix nine security vulnerabilities, including a critical command injection flaw in the SNMP monitoring component. The vulnerability affects systems with SNMP notifications enabled and could allow attackers to execute arbitrary commands. Users are urged to update to the latest version to mitigate potential exploi
     

Zimbra 10.1.20 patches multiple security issues, including a critical command injection bug

21 de Julho de 2026, 15:25

Zimbra patched nine flaws in version 10.1.20, including a critical SNMP monitoring command injection issue enabling arbitrary command execution.

Zimbra released version 10.1.20 to fix nine security vulnerabilities, including a critical command injection flaw in the SNMP monitoring component.

The vulnerability affects systems with SNMP notifications enabled and could allow attackers to execute arbitrary commands. Users are urged to update to the latest version to mitigate potential exploitation risks.

Other issues fixed in this release include multiple cross-site scripting (XSS) vulnerabilities affecting the Classic Web Client, which could allow attackers to execute malicious scripts through crafted attachment filenames, fields, or rendered content under specific conditions. The update also addresses a mail forwarding restriction bypass that could enable authenticated users to exfiltrate emails despite configured restrictions, as well as security issues involving access controls in the EWS extension, mailbox delegation authorization, and a server-side request forgery (SSRF) flaw in the Nextcloud integration.

In early July, Zimbra released version 10.1.19 to fix a critical stored XSS vulnerability in its Classic Web Client, which is widely used to access Zimbra Collaboration. The flaw can be exploited by sending specially crafted emails that execute malicious code when opened in the Classic UI.  Successful exploitation could allow attackers to access to mailbox information, session data, or account settings.

Google’s Threat Analysis Group discovered the vulnerability.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, command injection)

  • ✇Security Affairs
  • Update Now: Critical Zimbra Classic Web Client Flaw Could Expose Mailboxes Pierluigi Paganini
    Zimbra addressed a critical stored XSS vulnerability in its Classic Web Client that lets malicious emails execute code when opened. Zimbra has released version 10.1.19 to fix a critical stored XSS vulnerability in its Classic Web Client, which is widely used to access Zimbra Collaboration. The flaw, which has not yet received a CVE ID, can be exploited by sending specially crafted emails that execute malicious code when opened in the Classic UI.  Successful exploitation could allow attackers
     

Update Now: Critical Zimbra Classic Web Client Flaw Could Expose Mailboxes

10 de Julho de 2026, 17:42

Zimbra addressed a critical stored XSS vulnerability in its Classic Web Client that lets malicious emails execute code when opened.

Zimbra has released version 10.1.19 to fix a critical stored XSS vulnerability in its Classic Web Client, which is widely used to access Zimbra Collaboration. The flaw, which has not yet received a CVE ID, can be exploited by sending specially crafted emails that execute malicious code when opened in the Classic UI.  Successful exploitation could allow attackers to access to mailbox information, session data, or account settings.

“The update fixes a security issue in the Classic Web Client where a specially crafted email could run malicious code when the email is opened. If exploited, it could allow access to mailbox information, session data, or account settings.” reads the advisory

“We strongly recommend all customers to upgrade to ZCS v10.1.19 to ensure they have received the latest security patches, bug fixes, and enhancements.”

Google’s Threat Analysis Group discovered the vulnerability.

Although there is no evidence of active exploitation yet, organizations using the Classic Web Client should update as soon as possible.

Since the beginning of 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added [1, 2, 3] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog:

  • CVE-2025-68645 (CVSS score of 8.8) Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability
  • CVE-2020-7796 (CVSS score of 9.8) Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability
  • CVE-2025-66376 (CVSS score of 7.2) Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability.

In March, Russia-linked APT group, likely APT28  (aka UAC-0001, aka Fancy BearPawn StormSofacy GroupSednit, BlueDelta, and STRONTIUM), exploited the vulnerability CVE-2025-66376 in attacks against entities in Ukraine. Attackers used JavaScript in phishing emails to silently harvest credentials, session tokens, 2FA codes, saved passwords, and 90 days of mailbox data. Then they exfiltrated stolen data via DNS and HTTPS.

A national maritime agency was targeted on January 22 using a compromised student email. Seqrite Labs tracked this campaign as Operation GhostMail.

A phishing email targeted Ukraine’s State Hydrology Agency, part of critical infrastructure, using a compromised student account to appear legitimate. The message hid malicious JavaScript in the HTML body, exploiting a Zimbra XSS flaw (CVE-2025-66376).

Once opened, it executed in the user’s session, stealing credentials, tokens, emails, and 2FA data. The multi-stage payload used SOAP requests, DNS and HTTPS exfiltration, and enabled persistent access, allowing attackers to monitor accounts and extract up to 90 days of emails.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, XSS)

❌
❌