CyberNotableConfirmedDeveloping
9.5
Critical command injection vulnerability identified in Zimbra Collaboration Suite
The Hacker News·1 day ago
Zimbra has issued a security update addressing multiple high-severity vulnerabilities, including command injection, cross-site scripting (XSS), and server-side request forgery (SSRF). These flaws could allow unauthorized actors to compromise mail servers if left unpatched. The urgency of the update depends on the exposure of specific Zimbra instances to public networks.