Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-05 · 02:16 UTC
articleTotal: 1184 reports

Filtered Reports

8 / 9 results
Active filter:vendor: zimbra✕ clear
CISA orders 3-day patch for exploited Zimbra RCE (CVE-2026-73570)criticalbug_reportVulnerability
bug_reportVulnerability

CISA orders 3-day patch for exploited Zimbra RCE (CVE-2026-73570)

Zimbra Collaboration Suite (ZCS) versions prior to 10.1.20. Exploitation requires SNMP notifications to be enabled. Over 12,000 Zimbra servers exposed online; 270+ confirmed compromised instances detected by Shadowserver.

Zimbra24 Aug · 08:45 UTC
Zimbra SNMP flaw CVE-2026-73570 under active exploitation for RCEhighbug_reportVulnerability
bug_reportVulnerability

Zimbra SNMP flaw CVE-2026-73570 under active exploitation for RCE

Zimbra Collaboration Server (ZCS) versions before 10.1.20, only when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Unauthenticated remote attackers can exploit this command injection flaw.

CVE-2026-7357020 Aug · 11:24 UTC
Zimbra RCE flaw CVE-2026-73570 actively exploited in the wildcriticalbug_reportVulnerability
bug_reportVulnerability

Zimbra RCE flaw CVE-2026-73570 actively exploited in the wild

Zimbra Collaboration Suite (ZCS) versions prior to 10.1.20. Affects servers with SNMP notifications enabled. Over 12,100 Zimbra servers exposed online, primarily in Europe (4,382) and Asia (4,492). Impacts businesses and government agencies globally.

Zimbra20 Aug · 07:46 UTC
Zimbra Collaboration RCE under active exploitation, patch immediatelycriticalbug_reportVulnerability
bug_reportVulnerability

Zimbra Collaboration RCE under active exploitation, patch immediately

Zimbra Collaboration Suite - specific vulnerable versions not disclosed in advisory. Remote code execution vulnerability affecting internet-facing Zimbra instances.

Zimbra19 Aug · 11:28 UTC
Russian Espionage Group Exploited Zimbra Zero-Day for Email Theftcriticalperson_alertThreat Actor
person_alertThreat Actor

Russian Espionage Group Exploited Zimbra Zero-Day for Email Theft

A Russian state-sponsored espionage group conducted a sustained campaign exploiting a zero-day vulnerability in Zimbra's webmail client. The actor, tracked as TA488 by Proofpoint and CL-STA-1114 by Unit 42, operated undetected for at least five month…

Zimbra23 Jul · 16:36 UTC
Laundry Bear exploits Zimbra XSS zero-day for email thefthighperson_alertThreat Actor
person_alertThreat Actor

Laundry Bear exploits Zimbra XSS zero-day for email theft

Laundry Bear (also tracked as Void Blizzard by Microsoft) is a Russian state-sponsored APT group first publicly attributed by Dutch intelligence agencies in May 2025 following their 2024 compromise of the Dutch National Police.

Zimbra23 Jul · 14:49 UTC
Russian cyberespionage campaign targets Zimbra via JavaScript injectionhighperson_alertThreat Actor
person_alertThreat Actor

Russian cyberespionage campaign targets Zimbra via JavaScript injection

This campaign is attributed by Unit 42 to Russian cyberespionage interests. The actor's motivation centers on intelligence gathering through compromise of email infrastructure.

Zimbra23 Jul · 12:10 UTC
Zimbra 10.1.20 patches critical SNMP command injection and 4 XSS flawscriticalbug_reportVulnerability
bug_reportVulnerability

Zimbra 10.1.20 patches critical SNMP command injection and 4 XSS flaws

Zimbra Collaboration Suite versions prior to 10.1.20. Critical impact: SNMP monitoring component when SNMP notifications are enabled. Additional impact: four XSS vulnerabilities affecting the web interface.

Zimbra21 Jul · 11:18 UTC