Vulnerabilities Organizations Warned of Exploited Cisco, Kentico, Zimbra Vulnerabilities CISA expanded the KEV catalog with eight flaws, but five of them have been flagged as exploited before. Ionut ArghireApril 21, 2026
Malware & Threats Russian APT Exploits Zimbra Vulnerability Against Ukraine Insufficient sanitization of CSS content within HTML emails leads to inline script execution when the message is opened in a browser. Ionut ArghireMarch 19, 2026
Vulnerabilities Organizations Warned of Exploited Zimbra Collaboration Vulnerability CISA has added the Zimbra flaw to the KEV catalog along with three other bugs exploited in the wild. Ionut ArghireJanuary 23, 2026
Email Security Critical Zimbra Vulnerability Exploited One Day After PoC Release A critical-severity vulnerability in Zimbra has been exploited in the wild to deploy a web shell on vulnerable servers. Ionut ArghireOctober 2, 2024
Email Security Zimbra Zero-Day Exploited to Hack Government Emails Google says a Zimbra zero-day from earlier this year, CVE-2023-37580, was exploited in several campaigns to hack government emails. Eduard KovacsNovember 16, 2023
Vulnerabilities Zimbra Patches Exploited Zero-Day Vulnerability Zimbra has released patches for a cross-site scripting (XSS) vulnerability that has been exploited in malicious attacks. Ionut ArghireJuly 28, 2023
Vulnerabilities Google Researchers Discover In-the-Wild Exploitation of Zimbra Zero-Day Google researchers have discovered that a Zimbra zero-day vulnerability has been exploited in the wild, with users being advised to manually patch their installations. Eduard KovacsJuly 14, 2023