logo

Zimbra 0-day used to target international government organizations

ID: 74783fa1-a268-54f1-b7fc-c73dbe5c1dca

STIX ID: report--74783fa1-a268-54f1-b7fc-c73dbe5c1dca

Feed Name: Google's Threat Analysis Group (TAG)

Threat Score
70/100

Date Published: 2023-11-16

Date Updated: 2026-04-27

Author: Clement Lecigne

...
...

Google TAG identified at least four campaigns exploiting CVE-2023-37580 (a reflected XSS in Zimbra mail servers), including attacks that began after a fix was pushed to GitHub but before Zimbra’s public advisory. The report highlights ongoing active exploitation of mail-server XSS vulnerabilities, the attackers’ monitoring of open-source repositories to exploit unreleased fixes, and urges organizations to apply patches promptly while noting that TAG added affected sites to Safe Browsing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.