logo

Zimbra RCE Vuln Under Attack Needs Immediate Patching

ID: e6ee9418-14eb-53ea-a07f-871b595949a0

STIX ID: report--e6ee9418-14eb-53ea-a07f-871b595949a0

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2024-10-01

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Active exploitation of a critical Zimbra remote code execution (CVE-2024-45519) in the postjournal service is ongoing: attackers send spoofed emails containing base64-encoded payloads in the CC field to induce command injection, install web shells that accept commands via cookies, and run arbitrary code. Security vendors (Proofpoint, ProjectDiscovery, HarfangLab) observed exploitation beginning Sept. 28, published indicators (including an attacker IP) and a proof-of-concept, and Zimbra has released patches — administrators are urged to apply them immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.