Unpatched Zimbra Collaboration Suite RCE CVE-2022Security Affairs·Oct 16, 13:26 UTC · Oct 16, 2022Vulnerability in the wildCVE-2022-41352CVE-2015-119760
Zimbra urges customers to manually fix actively exploited zeroSecurity Affairs·Jul 13, 20:12 UTC · Jul 13, 2023Exploit / PoC in the wildCVE-2022-41352CVE-2022-27925160
Threat actors hacked hundreds of servers by exploiting Zimbra CVE-2022Security Affairs·Oct 16, 14:09 UTC · Oct 16, 2022Threat actor in the wildCVE-2022-41352CVE-2015-119760
Critical Zimbra Postjournal flaw CVE-2024-45519 actively exploited in the wild. Patch it now!Security Affairs·Oct 2, 09:21 UTC · Oct 2, 2024Exploit / PoC in the wildCVE-2024-4551960
Experts warn of mass exploitation of an RCE flaw in Zimbra Collaboration SuiteSecurity Affairs·Aug 12, 08:00 UTC · Aug 12, 2022Vulnerability in the wildCVE-2022-27925CVE-2022-37042CVE-2022-2792460
Unpatched Zimbra RCE bug exploited by attackers (CVE-2022-41352)Help Net Security·Oct 14, 14:18 UTC · Oct 14, 2022Vulnerability in the wildCVE-2022-41352CVE-2022-30333CVE-2015-1197160
Russian APT targets Ukraine via Zimbra XSS flaw CVE-2025Security Affairs·Mar 19, 14:48 UTC · Mar 19, 2026Vulnerability in the wildCVE-2025-6637660
U.S. CISA adds Synacor Zimbra Collaboration flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Oct 7, 05:24 UTC · Oct 7, 2024Exploit / PoC in the wildCVE-2024-4551960
European governments targeted by Chinese hackers with a Zimbra webmail zeroThe Record·Jan 17, 00:00 UTC · Jan 17, 2023Exploit / PoC60
Hackers Exploiting Unpatched RCE Flaw in Zimbra Collaboration SuiteThe Hacker News·Oct 10, 03:51 UTC · Oct 10, 2022Vulnerability in the wildCVE-2022-41352CVE-2022-30333160
Zimbra zero-day exploited to steal government emails by 4 groupsSecurity Affairs·Nov 16, 20:49 UTC · Nov 16, 2023Exploit / PoCCVE-2023-3758060
CISA orders civilian agencies to patch Zimbra bug after mass exploitationThe Record·Jan 11, 00:00 UTC · Jan 11, 2023Vulnerability in the wildCVE-2022-37042CVE-2022-27925CVE-2022-2792460
Zimbra zero-day actively exploited by an alleged Chinese threat actorSecurity Affairs·Feb 4, 09:54 UTC · Feb 4, 2022Exploit / PoC in the wild60
Critical Zimbra RCE vulnerability under mass exploitation (CVE-2024-45519)Help Net Security·Oct 2, 00:00 UTC · Oct 2, 2024Vulnerability in the wildCVE-2024-4551960
Zimbra fixed actively exploited zero-day CVE-2023Security Affairs·Jul 27, 21:49 UTC · Jul 27, 2023Exploit / PoC in the wildCVE-2023-3875060
CISA adds Zimbra bug to Known Exploited Vulnerabilities CatalogSecurity Affairs·Aug 5, 13:03 UTC · Aug 5, 2022Exploit / PoC in the wildCVE-2022-2792460
US Agencies Warn of Laundry Bear Campaign Targeting Unpatched Zimbra ServersSecurity Affairs·Jul 24, 08:31 UTC · Jul 24, 2026Vulnerability in the wildCVE-2025-6637660
Update Now: Critical Zimbra Classic Web Client Flaw Could Expose MailboxesSecurity Affairs·Jul 10, 20:42 UTC · Jul 10, 2026Data breach in the wildCVE-2025-68645CVE-2020-7796CVE-2025-6637660
U.S. CISA adds Synacor Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Oct 7, 21:39 UTC · Oct 7, 2025Exploit / PoC in the wildCVE-2025-2791560
Zimbra users targeted in zeroSecurity Affairs·Oct 7, 21:32 UTC · Oct 7, 2025Exploit / PoCCVE-2025-2791560
Zero-Day Flaw in Zimbra Email Software Exploited by Four Hacker GroupsThe Hacker News·Nov 17, 03:48 UTC · Nov 17, 2023Exploit / PoCCVE-2023-3758060
Critical XSS vulnerability in Zimbra exploited in the wild (CVE-2023-34192)Help Net Security·Jul 17, 00:00 UTC · Jul 17, 2023Exploit / PoC in the wildCVE-2023-34192CVE-2022-24682CVE-2022-41352+1 CVEs160
Researchers Warn of Ongoing Mass Exploitation of Zimbra RCE VulnerabilityThe Hacker News·Aug 12, 06:14 UTC · Aug 12, 2022Vulnerability in the wildCVE-2022-27925CVE-2022-37042CVE-2022-2792460
Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User SessionsThe Hacker News·Jul 11, 06:45 UTC · Jul 11, 2026Exploit / PoC in the wildCVE-2025-27915CVE-2023-37580CVE-2024-2744360
Zimbra Zero-Day Exploited to Target Brazilian Military via Malicious ICS FilesThe Hacker News·Oct 10, 06:52 UTC · Oct 10, 2025Exploit / PoC in the wildCVE-2025-2791560
Researchers Warn of Ongoing Attacks Exploiting Critical Zimbra Postjournal FlawThe Hacker News·Oct 4, 06:25 UTC · Oct 4, 2024Exploit / PoC in the wildCVE-2024-4551960
Hackers target Greece, Tunisia, Moldova, Vietnam and Pakistan with Zimbra zeroThe Record·Nov 16, 17:06 UTC · Nov 16, 2023Exploit / PoCCVE-2023-37580CVE-2022-2468260
Zimbra Releases Patch for Actively Exploited Vulnerability in its Collaboration SuiteThe Hacker News·Oct 17, 09:50 UTC · Oct 17, 2022Vulnerability in the wildCVE-2022-41352CVE-2015-1197160
Zimbra RCE Vulnerability Exploited Without Admin PrivilegesInfosecurity Magazine·Aug 11, 17:30 UTC · Aug 11, 2022Vulnerability in the wildCVE-2022-27925CVE-2022-3704260
Zimbra Releases Security Updates for SQL Injection, Stored XSS, and SSRF VulnerabilitiesThe Hacker News·Feb 10, 09:09 UTC · Feb 10, 2025VulnerabilityCVE-2025-25064CVE-2025-2506560
Zimbra Warns of Critical Zero-Day Flaw in Email Software Amid Active ExploitationThe Hacker News·Nov 16, 15:50 UTC · Nov 16, 2023Exploit / PoC in the wildCVE-2023-20214CVE-2023-3758060
New Zimbra Email Vulnerability Could Let Attackers Steal Your Login CredentialsThe Hacker News·Jun 15, 00:00 UTC · Jun 15, 2022VulnerabilityCVE-2022-2792460
Hackers Exploited 0-Day Vulnerability in Zimbra Email Platform to Spy on UsersThe Hacker News·Feb 4, 13:18 UTC · Feb 4, 2022Vulnerability55
Zimbra 10.1.20 patches multiple security issues, including a critical command injection bugSecurity Affairs·Jul 21, 18:25 UTC · Jul 21, 2026Vulnerability55
Russian hackers exploit Zimbra flaw to breach Ukrainian maritime agencyThe Record·Mar 19, 12:41 UTC · Mar 19, 2026VulnerabilityCVE-2025-6637660
U.S. CISA adds Google Chromium CSS, Microsoft Windows, TeamT5 ThreatSonar Anti-Ransomware, and Zimbra flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Feb 18, 10:55 UTC · Feb 18, 2026Ransomware in the wildCVE-2008-0015CVE-2020-7796CVE-2024-7694+1 CVEs60
Attackers exploit critical Zimbra vulnerability using cc’d email addressesArs Technica · Security·Oct 2, 21:50 UTC · Oct 2, 2024Vulnerability in the wildCVE-2024-4551960
CISA adds recently disclosed Zimbra bug to its Exploited Vulnerabilities CatalogThe Hacker News·Mar 1, 04:37 UTC · Mar 1, 2022Vulnerability in the wildCVE-2022-24682CVE-2017-8570CVE-2017-0222+1 CVEs60
Zimbra Patches Critical SNMP Command Injection and Four XSS VulnerabilitiesThe Hacker News·Jul 21, 13:18 UTC · Jul 21, 2026Vulnerability in the wildCVE-2026-5005560
CISA Warns of Zimbra, SharePoint Flaw Exploits; Cisco ZeroThe Hacker News·Mar 20, 04:36 UTC · Mar 20, 2026Advisory in the wildCVE-2025-66376CVE-2026-20963CVE-2026-20131+5 CVEs60