VYPR
breachPublished Sep 24, 2026· 1 source

Zimbra Vulnerabilities Enable Sophisticated Business Email Compromise Attacks

Over 50 vulnerabilities in Zimbra Collaboration Suite allow attackers to impersonate senders, alter documents, and rewrite communications, enabling advanced Business Email Compromise (BEC) attacks.

Rapid7 researchers have uncovered a significant security weakness within the Zimbra Collaboration Suite, detailing over 50 vulnerabilities that drastically alter the landscape of Business Email Compromise (BEC) attacks. Traditionally, BEC actors breach mailboxes to monitor communications and orchestrate financial fraud. However, these newly identified flaws empower attackers to move beyond passive observation and actively rewrite an organization's digital reality, impersonating senders, manipulating inbox visibility, and altering critical documents and calendar entries without needing valid credentials.

The implications of these vulnerabilities are profound, transforming BEC from a simple financial scam into a sophisticated psychological operation. Attackers can now send emails as company executives, and crucially, control whether these fraudulent messages appear in sent folders. This allows them to create convincing scenarios where a CFO might appear to have authorized a transaction, while simultaneously having the ability to erase the digital trail, leaving victims questioning their own actions and creating a conflict of evidence that paralyzes an organization's response.

Several specific vulnerabilities have been highlighted as particularly dangerous and are already being exploited in the wild. CVE-2024-45519, a command injection flaw in the postjournal service, allows unauthenticated command execution. Proofpoint observed attackers leveraging this by embedding base64 payloads in email CC fields, leading to its inclusion in CISA's Known Exploited Vulnerabilities (KEV) catalog. Similarly, CVE-2025-27915, a stored cross-site scripting (XSS) vulnerability triggered by a crafted .ICS attachment, was used as a zero-day against Brazilian military targets to steal mail and set up hidden forwarding rules. CISA added this to KEV in October 2025.

Further compounding the threat is CVE-2026-73570, an unauthenticated command injection vulnerability within SNMP notification handling. CISA issued an urgent alert for this flaw, giving federal agencies only three days to patch, and Shadowserver has already detected over 260 compromised instances. These recent discoveries echo past exploitation trends, such as the widespread abuse of CVE-2022-27925 and CVE-2022-37042 in 2022, which allowed attackers to gain remote code execution and deploy malicious shells on Zimbra servers.

The impact extends beyond email manipulation. Zimbra's collaborative features mean attackers can also target shared documents and calendars. The ability to plant a fake financial summary or HR memo directly into an executive's enterprise drive, and then have a trusted peer reference it in an email, creates a powerful and layered deception. This manufactured evidence, combined with manipulated communications, makes it significantly harder for organizations to discern truth from fabrication.

"Calendar warfare," as described by researchers, is another critical facet of these attacks. Attackers can modify or delete calendar events without triggering expected notifications, or even flip RSVP statuses. This can lead to key personnel missing crucial meetings or falling victim to sophisticated phishing attempts embedded within seemingly legitimate calendar invites, such as malicious Zoom links disguised as meeting invitations.

Collectively, these vulnerabilities transform Zimbra from a communication platform into a tool for manufacturing an "enterprise reality." By leveraging the inherent trust users place in their collaboration suite, attackers can orchestrate complex deceptions that undermine decision-making processes and facilitate large-scale fraud. The research underscores the critical need for organizations to promptly address these vulnerabilities and reassess their security posture around email and collaboration systems, which have become central systems of record.

CISA has added CVE-2024-45519, CVE-2025-27915, and CVE-2026-73570 to its KEV catalog, signaling their active exploitation and the urgency for remediation. Organizations using Zimbra Collaboration Suite are strongly advised to apply the latest security patches and review their configurations for any signs of compromise.

Synthesized by Vypr AI