Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
8 / 9 results
criticalbug_reportVulnerabilityCISA orders 3-day patch for exploited Zimbra RCE (CVE-2026-73570)
Zimbra Collaboration Suite (ZCS) versions prior to 10.1.20. Exploitation requires SNMP notifications to be enabled. Over 12,000 Zimbra servers exposed online; 270+ confirmed compromised instances detected by Shadowserver.
highbug_reportVulnerabilityZimbra SNMP flaw CVE-2026-73570 under active exploitation for RCE
Zimbra Collaboration Server (ZCS) versions before 10.1.20, only when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Unauthenticated remote attackers can exploit this command injection flaw.
criticalbug_reportVulnerabilityZimbra RCE flaw CVE-2026-73570 actively exploited in the wild
Zimbra Collaboration Suite (ZCS) versions prior to 10.1.20. Affects servers with SNMP notifications enabled. Over 12,100 Zimbra servers exposed online, primarily in Europe (4,382) and Asia (4,492). Impacts businesses and government agencies globally.
criticalbug_reportVulnerabilityZimbra Collaboration RCE under active exploitation, patch immediately
Zimbra Collaboration Suite - specific vulnerable versions not disclosed in advisory. Remote code execution vulnerability affecting internet-facing Zimbra instances.
criticalperson_alertThreat ActorRussian Espionage Group Exploited Zimbra Zero-Day for Email Theft
A Russian state-sponsored espionage group conducted a sustained campaign exploiting a zero-day vulnerability in Zimbra's webmail client. The actor, tracked as TA488 by Proofpoint and CL-STA-1114 by Unit 42, operated undetected for at least five month…
highperson_alertThreat ActorLaundry Bear exploits Zimbra XSS zero-day for email theft
Laundry Bear (also tracked as Void Blizzard by Microsoft) is a Russian state-sponsored APT group first publicly attributed by Dutch intelligence agencies in May 2025 following their 2024 compromise of the Dutch National Police.
highperson_alertThreat ActorRussian cyberespionage campaign targets Zimbra via JavaScript injection
This campaign is attributed by Unit 42 to Russian cyberespionage interests. The actor's motivation centers on intelligence gathering through compromise of email infrastructure.
criticalbug_reportVulnerabilityZimbra 10.1.20 patches critical SNMP command injection and 4 XSS flaws
Zimbra Collaboration Suite versions prior to 10.1.20. Critical impact: SNMP monitoring component when SNMP notifications are enabled. Additional impact: four XSS vulnerabilities affecting the web interface.