Zimbra has addressed a critical stored cross-site scripting (XSS) vulnerability affecting its Classic Web Client, used globally by businesses and government agencies. This vulnerability lets attackers execute malicious code with specially crafted emails. Zimbra users are urged to upgrade to version 10.1.19 to mitigate this risk.
Beyond the critical XSS vulnerability, Zimbra has rolled out additional security updates in version 10.1.20. These patches cover nine vulnerabilities, including a serious command injection flaw in the SNMP monitoring component, which could allow unauthenticated users to execute OS commands remotely.
These updates also address four other XSS flaws in the Classic Web Client, security loopholes in email forwarding, and access control issues, significantly bolstering security for users of the platform.
Zimbra's updates emphasize the necessity for prompt user action to prevent potential exploits. The broad user base of Zimbra's email and collaboration suite underscores the importance of securing installations against these vulnerabilities to avoid data compromises.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Russian state-sponsored hackers, identified as TA488, are actively exploiting a maximum-severity vulnerability (CVE-2026-42897) in Microsoft Exchange Server to compromise unpatched systems and steal credentials. The attacks utilize a "half-click" exploit, where merely opening an email in Outlook Web Access triggers the installation of a sophisticated new JavaScript-based implant called OWAReaper. This development indicates an advancement in the group's capabilities and poses a significant threat to organizations using vulnerable Exchange servers.
Russian threat actors, identified as Laundry Bear (TA488), are exploiting a cross-site scripting (XSS) vulnerability (CVE-2026-42897) in Microsoft Outlook Web Access (OWA) to target government entities and various sectors in the U.S. and Europe. This activity, which began in July 2026, allows the attackers to maintain access to mailboxes even after credential rotation, indicating an advancement in their exploitation techniques.
The Russian state-sponsored hacking group Laundry Bear is exploiting a zero-day cross-site scripting (XSS) vulnerability, CVE-2026-42897, in Exchange Outlook Web Access (OWA) to deploy a backdoor named OWAReaper. This vulnerability allows arbitrary JavaScript execution when users open specially crafted emails, impacting government entities and various companies in the U.S. and Europe.
The Russian state-linked hacking group Laundry Bear (TA488/Void Blizzard) exploited a vulnerability in Microsoft Outlook Web Access (OWA) using a new JavaScript implant called OWAReaper, targeting government, telecommunications, financial, hospitality, and aerospace sectors. This activity occurred shortly after their previously reported attacks on Zimbra Collaboration Suite users, indicating an improvement in the group's capabilities and a broader scope of targets.
A Russian state-supported espionage group exploited a zero-day vulnerability in Zimbra's webmail client for at least five months in 2025, stealing email and two-factor authentication codes from Western government and commercial organizations. The flaw, CVE-2025-66376, allowed attackers to execute JavaScript by simply viewing a malicious email, compromising user mailboxes.
Federal agencies from multiple Western nations have issued an alert regarding a Russian state-aligned hacking group, Laundry Bear, targeting governmental and commercial organizations through zero-click phishing emails exploiting a vulnerability in Zimbra Collaboration Suite's webmail platform. This campaign, which previously targeted Ukrainian entities, is now focusing on U.S. and NATO organizations, indicating espionage activities.
CISA has issued a warning that the Russian state-sponsored hacking group Laundry Bear (also known as Void Blizzard) is exploiting a zero-click vulnerability in Zimbra Collaboration email servers to steal account data. This exploitation, combined with phishing, affects various organizations including those in the Defense Industrial Base, government, and education, allowing attackers to exfiltrate emails and bypass MFA.
Zimbra has released updates for nine security vulnerabilities, including a critical SNMP command injection flaw and four cross-site scripting (XSS) vulnerabilities. These fixes are essential to prevent potential exploits, especially given the history of XSS vulnerabilities being targeted in similar software.
Zimbra has released patches for multiple critical vulnerabilities in its Collaboration Suite, including a command injection flaw that allows unauthenticated attackers to execute commands remotely. The update, ZCS 10.1.20, also fixes several cross-site scripting vulnerabilities and an email forwarding restriction bypass.
Zimbra has patched a critical stored cross-site scripting vulnerability in its Classic Web Client that could allow zero-click code execution via a malicious email. The flaw, which has not yet received a CVE identifier, raises significant security concerns due to potential unauthorized access to user data.
Zimbra has announced updates to fix a critical stored cross-site scripting (XSS) vulnerability in the Classic Web Client. This flaw allows specially crafted emails to execute malicious code in user sessions, risking exposure of sensitive information and account settings.
Zimbra announced a patch for a critical stored XSS vulnerability affecting its Classic Web Client. Attackers could exploit this flaw to execute malicious code via specially crafted emails, leading to potential data theft. Customers using the Classic Web Client are urged to upgrade to version 10.1.19 to secure their systems.