Zimbra vulnerabilities
8 CVEs tracked
Zimbra appears in our reporting primarily as a target of the Russian state-sponsored espionage group Laundry Bear (Void Blizzard/TA488). The main theme is the group's exploitation of a zero-click zero-day (CVE-2025-66376) over five months to steal emails, passwords, and 2FA codes from Western organizations. Defenders must also focus on other patched vulnerabilities, including a critical SNMP command injection (CVE-2026-73570) and SOAP authorization bypass issues enabling user impersonation and XSS (CVE-2026-73571, CVE-2026-73572). Prioritizing patching and monitoring for targeted phishing associated with these campaigns is crucial.
Azərbaycanca: Zimbra, hesabatlarımızda Rusiyaya bağlı Laundry Bear (Void Blizzard/TA488) kibercasus qrupunun hədəfində olan əsas e-poçt platforması kimi önə çıxır. Əsas hadisə, qrupun 5 ay ərzində sıfır klikli zero-day (CVE-2025-66376) istismar edərək e-poçt, parol və 2FA kodlarını oğurlamasıdır. Müdafiəçilər həmçinin kritik SNMP əmr inyeksiyası (CVE-2026-73570) və istifadəçi imitasiyasına və XSS-ə səbəb olan SOAP avtorizasiya bypass (CVE-2026-73571, CVE-2026-73572) daxil olmaqla yamaqlanmış boşluqlara diqqət yetirməlidirlər. Patch idarəetməsini sürətləndirmək və xüsusilə yüksək dəyərli hədəflərə qarşı məqsədli fişinq əlamətlərini izləmək vacibdir.
This vendor's CVEs8
This hub is built from skopnix's own reporting on Zimbra: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.