logo

Mass Exploitation of (Un)authenticated Zimbra RCE: CVE-2022-27925

ID: 06b35471-77e0-5f7d-8fac-843239ce6fc7

STIX ID: report--06b35471-77e0-5f7d-8fac-843239ce6fc7

Feed Name: Volexity Blog

Threat Score
88/100

Date Published: 2022-08-10

Date Updated: 2026-05-01

...
...

**Volexity observed mass exploitation of Zimbra Collaboration Suite where an initially authenticated RCE (CVE-2022-27925) could be leveraged without credentials due to an authentication bypass (CVE-2022-37042), leading to webshell deployments and confirmed compromises of over 1,000 servers worldwide; the report explains the vulnerability mechanics, common webshell indicators, scanning methodology, and remediation steps including patches and forensic actions.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.