Our takeCERT Polska reports active exploitation of a critical RCE in Zimbra Collaboration. Claimed but unconfirmed by any filing or second source; treat as unverified for now and review the advisory if you run Zimbra.Cyber Resilience desk
Sources (1)
- bleeping · bleeping
What this means for you — Security leader:If you run self-hosted Zimbra Collaboration Suite, apply CERT Polska's patches and review logs for exploitation immediately.
What this means for you — Lean IT orgs:If your email server is Zimbra, update it to the latest version right away or switch providers; this flaw lets attackers take control just by sending a message.
What this means for you — MSP:Check every client running on-premises Zimbra Collaboration Suite; patch to the versions listed in the CERT Polska advisory and scan for compromise.
What this means for you — Researcher:Monitor for post-exploitation activity tied to this Zimbra RCE; early exploitation reports come from CERT Polska.