The vulnerability has been classified under CWE-918 (Server-Side Request Forgery) and CWE-807 (Reliance on Untrusted Inputs in a Security Decision), indicating the severity of the trust boundary violations involved. While the connection to ransomware campaigns remains unknown, the SSRF nature of the vulnerability makes it particularly attractive to attackers seeking to establish initial footholds in enterprise environments. This type of vulnerability is particularly dangerous in cloud environments where metadata services often contain sensitive authentication tokens and configuration data. The vulnerability, tracked as CVE-2019-9621, poses significant risks to organizations using the popular email and collaboration platform. CISA alerts on an SSRF flaw (CVE-2019-9621) in Zimbra ZCS, actively exploited by attackers.
This Cyber News was published on cybersecuritynews.com. Publication date: Tue, 08 Jul 2025 09:50:11 +0000