Email security, Cloud Security
Actively exploited Zimbra zero-day addressed
Share
Patches have been issued by Zimbra for an actively exploited zero-day flaw in its Zimbra Collaboration Suite email servers two weeks after initial disclosure, reports BleepingComputer.
Attacks leveraging the reflected cross-site scripting bug, tracked as CVE-2023-38750, could result in internal JSP and XML file exposure, according to Zimbra, which only initially advised manual mitigation of the vulnerability on impacted mailbox nodes.
However, the flaw was noted by Google Threat Analysis Group researcher Maddie Stone to have been identified amid active exploitation. Attacks leveraging the flaw have prompted its inclusion in the Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities Catalog, with the agency urging the remediation of all vulnerable instances by Aug. 17.
"These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise," said CISA, which also advised the immediate patching of Ivanti Endpoint Manager Mobile instances earlier this week.
An In-Depth Guide to Cloud Security
Get essential knowledge and practical strategies to fortify your cloud security.
Related Events
Related Terms
Bring Your Own Device (BYOD)Cloud ComputingEavesdroppingEmail SpoofingGreynetInternet Message Access Protocol (IMAP)Post Office Protocol, Version 3 (POP3)SpamStore-and-ForwardGet daily email updates
SC Media's daily must-read of the most current and pressing daily news