Zimbra Collaboration (ZCS): Enterprise Email and Collaboration Suite
Zimbra Collaboration (ZCS) is a widely used email and collaboration platform. It is affected by CVE-2026-73570, a command injection vulnerability in the…
Zimbra Collaboration (ZCS) is a widely used email and collaboration platform. It is affected by CVE-2026-73570, a command injection vulnerability in the…
A now-patched command injection vulnerability in Zimbra Collaboration (ZCS), tracked as CVE-2026-73570 (CVSS 8.9), is under active exploitation in the wild, according…
The classic user interface of Zimbra collaboration software, exploited via CVE-2025-66376 by Laundry Bear to deploy ZimReaper.
Zimbra is an email and collaboration platform targeted by Laundry Bear using CVE-2025-66376 to deliver ZimReaper malware.
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign involving a malicious program disguised as a Notepad++…
ZimReaper is a malicious JavaScript payload delivered via CVE-2025-66376 in Zimbra's Classic UI. It harvests email communications and other sensitive data from…
Laundry Bear (also known as CL-STA-1114, TA488, UNK_PitStop, Void Blizzard) is a Russia-linked adversary that conducted a phishing campaign against Western government…
A Russian state-sponsored espionage group exploited a zero-day vulnerability in Zimbra's webmail client to steal emails, passwords, and two-factor authentication recovery codes…
CVE-2025-66376 is a stored cross-site scripting vulnerability in Zimbra's Classic UI. It was weaponized by the Russia-linked threat actor Laundry Bear to…
Zimbra has released security updates addressing nine vulnerabilities in Zimbra 10.1.20, including a critical command injection flaw in the Simple Network Management…