Zimbra SNMP Flaw CVE-2026-73570 Actively Exploited for Unauthenticated RCE
A now-patched command injection vulnerability in Zimbra Collaboration (ZCS), tracked as CVE-2026-73570 (CVSS 8.9), is under active exploitation in the wild, according…
A now-patched command injection vulnerability in Zimbra Collaboration (ZCS), tracked as CVE-2026-73570 (CVSS 8.9), is under active exploitation in the wild, according…
Russian threat actors linked to the exploitation of a Zimbra vulnerability have been observed exploiting CVE-2026-42897, a cross-site scripting (XSS) flaw in…
Zimbra is an email and collaboration platform targeted by Laundry Bear using CVE-2025-66376 to deliver ZimReaper malware.
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign involving a malicious program disguised as a Notepad++…
Laundry Bear (also known as CL-STA-1114, TA488, UNK_PitStop, Void Blizzard) is a Russia-linked adversary that conducted a phishing campaign against Western government…
A Russian state-sponsored espionage group exploited a zero-day vulnerability in Zimbra's webmail client to steal emails, passwords, and two-factor authentication recovery codes…
CVE-2025-66376 is a stored cross-site scripting vulnerability in Zimbra's Classic UI. It was weaponized by the Russia-linked threat actor Laundry Bear to…