Since July 2025, Russian state-backed hackers, known as Laundry Bear, have exploited a zero-click vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite to infiltrate Western government and commercial…
Russian state-backed hackers from APT28 are actively exploiting a high-severity stored cross-site scripting vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite (ZCS) to target Ukrainian government entities.…
A Russian state-linked advanced persistent threat (APT) has targeted a Ukrainian government agency through a cross-site scripting (XSS) vulnerability in the Zimbra Collaboration Suite, identified as CVE-2025-66376. The…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert regarding the active exploitation of three vulnerabilities in Cisco's Catalyst SD-WAN Manager, specifically CVE-2026-20122,…
Zimbra released version 10.1.20 to address nine security vulnerabilities, including a critical command injection flaw in the SNMP monitoring component. This vulnerability allows attackers to execute arbitrary commands…
A security vulnerability has been identified in Zimbra Collaboration Suite, affecting versions prior to 10.0.12, 10.1.4, and 8.8.15 Patch 47. This vulnerability allows remote attackers to exploit cross-site scripting…
The Cybersecurity and Infrastructure Security Agency (CISA) has added vulnerabilities affecting Google Chrome, Zimbra, ThreatSonar, and a Windows ActiveX module to its Known Exploited Vulnerabilities list. The…
A Local File Inclusion (LFI) vulnerability (CVE-2025-68645) has been identified in the Zimbra Collaboration Suite Webmail Classic UI, allowing unauthenticated attackers to exploit user-supplied request parameters.…