Zimbra urges customers to manually fix actively exploited zeroSecurity Affairs·Jul 13, 20:12 UTC · Jul 13, 2023Exploit / PoC in the wildCVE-2022-41352CVE-2022-27925160
Critical Zimbra Postjournal flaw CVE-2024-45519 actively exploited in the wild. Patch it now!Security Affairs·Oct 2, 09:21 UTC · Oct 2, 2024Exploit / PoC in the wildCVE-2024-4551960
U.S. CISA adds Synacor Zimbra Collaboration flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Oct 7, 05:24 UTC · Oct 7, 2024Exploit / PoC in the wildCVE-2024-4551960
European governments targeted by Chinese hackers with a Zimbra webmail zeroThe Record·Jan 17, 00:00 UTC · Jan 17, 2023Exploit / PoC60
Zimbra zero-day exploited to steal government emails by 4 groupsSecurity Affairs·Nov 16, 20:49 UTC · Nov 16, 2023Exploit / PoCCVE-2023-3758060
Zimbra zero-day actively exploited by an alleged Chinese threat actorSecurity Affairs·Feb 4, 09:54 UTC · Feb 4, 2022Exploit / PoC in the wild60
Zimbra fixed actively exploited zero-day CVE-2023Security Affairs·Jul 27, 21:49 UTC · Jul 27, 2023Exploit / PoC in the wildCVE-2023-3875060
CISA adds Zimbra bug to Known Exploited Vulnerabilities CatalogSecurity Affairs·Aug 5, 13:03 UTC · Aug 5, 2022Exploit / PoC in the wildCVE-2022-2792460
U.S. CISA adds Synacor Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Oct 7, 21:39 UTC · Oct 7, 2025Exploit / PoC in the wildCVE-2025-2791560
Zimbra users targeted in zeroSecurity Affairs·Oct 7, 21:32 UTC · Oct 7, 2025Exploit / PoCCVE-2025-2791560
Zero-Day Flaw in Zimbra Email Software Exploited by Four Hacker GroupsThe Hacker News·Nov 17, 03:48 UTC · Nov 17, 2023Exploit / PoCCVE-2023-3758060
Critical XSS vulnerability in Zimbra exploited in the wild (CVE-2023-34192)Help Net Security·Jul 17, 00:00 UTC · Jul 17, 2023Exploit / PoC in the wildCVE-2023-34192CVE-2022-24682CVE-2022-41352+1 CVEs160
Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User SessionsThe Hacker News·Jul 11, 06:45 UTC · Jul 11, 2026Exploit / PoC in the wildCVE-2025-27915CVE-2023-37580CVE-2024-2744360
Zimbra Zero-Day Exploited to Target Brazilian Military via Malicious ICS FilesThe Hacker News·Oct 10, 06:52 UTC · Oct 10, 2025Exploit / PoC in the wildCVE-2025-2791560
Researchers Warn of Ongoing Attacks Exploiting Critical Zimbra Postjournal FlawThe Hacker News·Oct 4, 06:25 UTC · Oct 4, 2024Exploit / PoC in the wildCVE-2024-4551960
Hackers target Greece, Tunisia, Moldova, Vietnam and Pakistan with Zimbra zeroThe Record·Nov 16, 17:06 UTC · Nov 16, 2023Exploit / PoCCVE-2023-37580CVE-2022-2468260
Zimbra Warns of Critical Zero-Day Flaw in Email Software Amid Active ExploitationThe Hacker News·Nov 16, 15:50 UTC · Nov 16, 2023Exploit / PoC in the wildCVE-2023-20214CVE-2023-3758060
CISA Adds Microsoft and Zimbra Flaws to KEV Catalog Amid Active ExploitationThe Hacker News·Feb 26, 04:33 UTC · Feb 26, 2025Exploit / PoC in the wildCVE-2024-49035CVE-2023-3419260
⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and MoreThe Hacker News·Jul 28, 05:26 UTC · Jul 28, 2026Exploit / PoC in the wildCVE-2026-16232CVE-2025-66376CVE-2026-54121+52 CVEs60
Bitter APT adds Bangladesh to their targetsCisco Talos·May 11, 12:00 UTC · May 11, 2022Exploit / PoCCVE-2017-11882CVE-2018-0798CVE-2018-0802+1 CVEs60
U.S. CISA adds Cisco Catalyst, Kentico Xperience, PaperCut NG/MF, Synacor ZCS, Quest KACE SMA, and JetBrains TeamCity flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Apr 21, 09:21 UTC · Apr 21, 2026Exploit / PoC in the wildCVE-2026-20133CVE-2023-27351CVE-2024-27199+5 CVEs60
RussianTA488 Returns With Persistent Outlook Web Access AttackInfosecurity Magazine·Jul 29, 15:10 UTC · Jul 29, 2026Exploit / PoCCVE-2026-4289760
Spies hack high-value mail servers using an exploit from yesteryearArs Technica · Security·May 15, 00:00 UTC · May 15, 2025Exploit / PoCCVE-2023-4377060
Winter Vivern APT exploited zero-day in Roundcube webmail software in recent attacksSecurity Affairs·Oct 26, 05:20 UTC · Oct 26, 2023Exploit / PoCCVE-2020-35730CVE-2022-27926CVE-2023-563160
Week in review: VirusTotal data leak, Citrix NetScaler zero-day exploitationHelp Net Security·Jul 23, 00:00 UTC · Jul 23, 2023Exploit / PoC in the wildCVE-2023-3519CVE-2023-29298CVE-2023-38203+3 CVEs60
Week in review: 3FA, Fortinet firewalls under attack, and the riskiest connected devicesHelp Net Security·Oct 16, 00:00 UTC · Oct 16, 2022Exploit / PoC in the wildCVE-2022-41033CVE-2022-40684CVE-2022-36067+1 CVEs160
Max-severity Exchange server flaw under active exploitation by Kremlin hackersArs Technica · Security·Jul 30, 20:57 UTC · Jul 30, 2026Exploit / PoC in the wildCVE-2026-4289760
Russian Hackers Exploit New ‘ZeroInfosecurity Magazine·Jul 23, 15:50 UTC · Jul 23, 2026Exploit / PoCCVE-2025-6637660
U.S. CISA adds Qualcomm and Broadcom VMware Aria Operations flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 4, 08:56 UTC · Mar 4, 2026Exploit / PoC in the wildCVE-2026-22719CVE-2026-2138560
CISA Adds Actively Exploited SolarWinds Web Help Desk RCE to KEV CatalogThe Hacker News·Feb 5, 03:59 UTC · Feb 5, 2026Exploit / PoC in the wildCVE-2025-40551CVE-2025-40536CVE-2025-40537+7 CVEs60
CISA Updates KEV Catalog with Four Actively Exploited Software VulnerabilitiesThe Hacker News·Jan 23, 15:24 UTC · Jan 23, 2026Exploit / PoC in the wildCVE-2025-68645CVE-2025-34026CVE-2025-31125+1 CVEs60
CISA Adds Four Critical Vulnerabilities to KEV Catalog Due to Active ExploitationThe Hacker News·Jul 8, 05:08 UTC · Jul 8, 2025Exploit / PoC in the wildCVE-2014-3931CVE-2016-10033CVE-2019-5418+3 CVEs60
CISA Adds Erlang SSH and Roundcube Flaws to Known Exploited Vulnerabilities CatalogThe Hacker News·Jun 12, 05:02 UTC · Jun 12, 2025Exploit / PoC in the wildCVE-2025-32433CVE-2024-42009CVE-2025-3102260
Critical 10-Year-Old Roundcube Webmail Bug Allows Authenticated Users Run Malicious CodeThe Hacker News·Jun 9, 12:15 UTC · Jun 9, 2025Exploit / PoC in the wildCVE-2025-49113CVE-2024-3738360
Multi-national warning issued over Russia’s targeting of logistics, tech firmsCyberScoop·May 21, 18:41 UTC · May 21, 2025Exploit / PoC in the wildCVE-2023-23397CVE-2023-3883160
⚡ Weekly Recap: Zero-Day Exploits, Insider Threats, APT Targeting, Botnets and MoreThe Hacker News·May 19, 14:35 UTC · May 19, 2025Exploit / PoC in the wildCVE-2025-30397CVE-2025-30400CVE-2025-32701+22 CVEs60
Kremlin-linked hackers target webmail servers of Eastern European government agenciesThe Record·May 15, 14:13 UTC · May 15, 2025Exploit / PoC60
Russian state threat group shifts focus to US, UK targetsCyberScoop·Feb 12, 17:58 UTC · Feb 12, 2025Exploit / PoC in the wildCVE-2024-1709CVE-2023-48788CVE-2021-34473+4 CVEs160
Microsoft Fixes 90 New Flaws, Including Actively Exploited NTLM and Task Scheduler BugsThe Hacker News·Nov 15, 00:00 UTC · Nov 15, 2024Exploit / PoC in the wildCVE-2024-43451CVE-2024-49039CVE-2024-21410+6 CVEs260
China's elite hackers expand target list to European UnionCyberScoop·Nov 7, 10:00 UTC · Nov 7, 2024Exploit / PoC in the wild60