<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>zimbra &#8211; First Hackers News</title>
	<atom:link href="https://firsthackersnews.com/category/vulnerability/zimbra/feed/" rel="self" type="application/rss+xml" />
	<link>https://firsthackersnews.com</link>
	<description>Latest cybersecurity news, real attacks, and practical IOCs—made simple and actionable.</description>
	<lastBuildDate>Fri, 12 Aug 2022 16:52:17 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://firsthackersnews.com/wp-content/uploads/2026/03/cropped-FHN_512x512-32x32.png</url>
	<title>zimbra &#8211; First Hackers News</title>
	<link>https://firsthackersnews.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Researchers Warn of Ongoing Mass Exploitation of Zimbra RCE Vulnerability</title>
		<link>https://firsthackersnews.com/zimbra-rce-vulnerability/</link>
					<comments>https://firsthackersnews.com/zimbra-rce-vulnerability/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Fri, 12 Aug 2022 16:52:16 +0000</pubDate>
				<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[IOC's]]></category>
		<category><![CDATA[Malicious extension]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[zimbra]]></category>
		<category><![CDATA[authentication bypass]]></category>
		<category><![CDATA[exploitation]]></category>
		<category><![CDATA[Patch]]></category>
		<category><![CDATA[patch update]]></category>
		<category><![CDATA[rce vulnerability]]></category>
		<category><![CDATA[security fix]]></category>
		<category><![CDATA[security vulnerability]]></category>
		<category><![CDATA[Zimbra]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=5318</guid>

					<description><![CDATA[<p>The US Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added two disadvantages of it Catalog of known vulnerabilities in useciting</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/zimbra-rce-vulnerability/">Researchers Warn of Ongoing Mass Exploitation of Zimbra RCE Vulnerability</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>The US Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added two disadvantages of it Catalog of known vulnerabilities in useciting evidence of active exploitation.</p>



<p>Two high-severity issues are related to vulnerabilities in Zimbra Collaboration, both of which can be linked to achieve unauthenticated remote code execution on compromised email servers –</p>



<ul class="wp-block-list"><li><a rel="noreferrer noopener" href="https://nvd.nist.gov/vuln/detail/CVE-2022-27925" target="_blank"><strong>CVE-2022-27925</strong></a> (CVSS score: 7.2) – Remote code execution (RCE) via mboximport from authenticated user (fixed in versions 8.8.15 Patch 31 and 9.0.0 Patch 24 released in March)</li><li><a rel="noreferrer noopener" href="https://nvd.nist.gov/vuln/detail/CVE-2022-37042" target="_blank"><strong>CVE-2022-37042</strong></a> – Authentication bypass in MailboxImportServlet (fixed in versions 8.8.15 Patch 33 and 9.0.0 Patch 26 released in August)</li></ul>



<p>Volexity explained “it was attainable to bypass authentication when accessing the same endpoint (mboximport) utilized by CVE-2022-27925,” and that the flaw “could be exploited with no legitimate administrative qualifications, as a result making the vulnerability appreciably additional critical in severity.”</p>



<p>“CVE-2022-27925 was originally mentioned as an RCE exploit necessitating authentication,” Volexity reported. “When merged with a individual bug, nonetheless, it became an unauthenticated RCE exploit that manufactured remote exploitation trivial.”</p>



<h2 class="wp-block-heading">Recommendation</h2>



<p>“If you are running a Zimbra version that is older than Zimbra 8.8.15 patch 33 or Zimbra 9.0.0 patch 26 you should update to the latest patch as soon as possible,” Zimbra <a href="https://blog.zimbra.com/2022/08/authentication-bypass-in-mailboximportservlet-vulnerability/" rel="noreferrer noopener" target="_blank">warned</a> earlier this week.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow"><p>Follow Us on:<strong> <a rel="noreferrer noopener" href="https://twitter.com/Info_FHNews" target="_blank">Twitter</a>,<a rel="noreferrer noopener" href="https://www.instagram.com/first_hackers_news/" target="_blank"> Instagram</a>, <a rel="noreferrer noopener" href="https://www.linkedin.com/in/firsthackers-news/" target="_blank">Facebook</a></strong> to get the latest security news!</p><p></p></blockquote>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/zimbra-rce-vulnerability/">Researchers Warn of Ongoing Mass Exploitation of Zimbra RCE Vulnerability</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/zimbra-rce-vulnerability/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
