Skip to content
Zimbra Collaboration Local File Inclusion

Zimbra Collaboration Local File Inclusion

Filestore.Fortinet January 30, 2026

Successful exploitation may allow threat actors to: • Leak sensitive files from the system WebRoot directory • Gain reconnaissance and foothold inside the targeted environment. • Potentially leverage exposed information for further exploitation or escalation. • A public proof-of-concept exploit is available, and active exploitation has been observed.

Recent news and incidents related to cybersecurity threats encompassing various events such as data breaches, cyber-attacks, security incidents, and vulnerabilities discovered.

Apply vendor patches immediately for all affected ZCS versions (Zimbra Collaboration (ZCS) 10.0 – 10.0.17- Zimbra Collaboration (ZCS) 10.1.0 – 10.1.12), and Fixed versions are 10.0.18 and 10.1.13.

January 28, 2026: FortiGuard released a Threat Signal Report.

January 23, 2026: CISA confirms active exploitation.

November 06, 2025: Zimbra Patch Release.

Mitigate security threats and vulnerabilities by leveraging the range of FortiGuard Services.

Assisted Response Services

Attack Surface Hardening

Information gathered from analyzing ongoing cybersecurity events including threat actors, their tactics, techniques, and procedures (TTPs), indicators of compromise (IOCs), malware and related vulnerabilities.

Sources of information in support and relation to this Outbreak and vendor.

Extracted Entities

Vulnerabilities (1)