<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Zimbra</title><description>Cybersecurity articles tagged #Zimbra on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Zimbra CVE-2026-73570 Actively Exploited: Patch Now</title><link>https://runtimerebel.com/blog/zimbra-cve-2026-73570-actively-exploited-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/zimbra-cve-2026-73570-actively-exploited-patch-now</guid><description>Active exploitation targets Zimbra servers via CVE-2026-73570, a high-severity flaw allowing unauthenticated RCE. Patch to v10.1.20 now.</description><pubDate>Thu, 20 Aug 2026 16:24:30 GMT</pubDate><category>Zimbra</category><category>Exploitation</category><category>Remote Code Execution</category><category>CVE-2026-73570</category><category>Zimbra Collaboration Suite</category></item><item><title>CVE-2025-66376: APT28 Exploits Zimbra Zero-Click for Espionage</title><link>https://runtimerebel.com/blog/cve-2025-66376-apt28-exploits-zimbra-zero-click-for-espionage</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2025-66376-apt28-exploits-zimbra-zero-click-for-espionage</guid><description>Russian state-sponsored actors exploit a zero-click Zimbra vulnerability (CVE-2025-66376) to exfiltrate sensitive webmail data from targeted organizations.</description><pubDate>Sat, 08 Aug 2026 08:33:35 GMT</pubDate><category>CVE-2025-66376</category><category>Zimbra</category><category>Cyber Espionage</category><category>Zero Click</category><category>Phishing</category></item><item><title>Multi-Threat Brief: AI Malware, Zimbra Exploits, Linux Kernel Flaws</title><link>https://runtimerebel.com/blog/multi-threat-brief-ai-malware-zimbra-exploits-linux-kernel-flaws</link><guid isPermaLink="true">https://runtimerebel.com/blog/multi-threat-brief-ai-malware-zimbra-exploits-linux-kernel-flaws</guid><description>Analysis of recent threats including DolphinX AI malware, state-sponsored Zimbra exploits, Siemens industrial switch vulnerabilities, and 400 Linux kernel flaws.</description><pubDate>Fri, 24 Jul 2026 17:42:24 GMT</pubDate><category>DolphinX</category><category>Emerald Sleet</category><category>Winter Vivern</category><category>UNC4841</category><category>Zimbra</category><category>Linux Kernel</category><category>Siemens ROX II</category><category>Industrial Control Systems</category><category>APT</category><category>Ransomware</category><category>LockBit</category></item><item><title>Zimbra Zero-Day Exploited by Laundry Bear Against US &amp; Ukraine</title><link>https://runtimerebel.com/blog/zimbra-zero-day-exploited-by-laundry-bear-against-us-ukraine</link><guid isPermaLink="true">https://runtimerebel.com/blog/zimbra-zero-day-exploited-by-laundry-bear-against-us-ukraine</guid><description>Russian state-sponsored group &apos;Laundry Bear&apos; exploits a Zimbra zero-day via &apos;half-click&apos; phishing, targeting US and Ukrainian entities for credential theft and backdoor…</description><pubDate>Fri, 24 Jul 2026 02:47:14 GMT</pubDate><category>Laundry Bear</category><category>Zimbra</category><category>Zero-Day</category><category>Phishing</category><category>US</category><category>Ukraine</category><category>State Sponsored</category></item><item><title>Russian APT Exploits Zimbra Zero-Day to Exfiltrate Mail and 2FA Codes</title><link>https://runtimerebel.com/blog/russian-apt-exploits-zimbra-zero-day-to-exfiltrate-mail-and-2fa-codes</link><guid isPermaLink="true">https://runtimerebel.com/blog/russian-apt-exploits-zimbra-zero-day-to-exfiltrate-mail-and-2fa-codes</guid><description>Russian state-supported actors leveraged a Zimbra Zero-Day to steal 90 days of email history and bypass security by exfiltrating 2FA recovery codes.</description><pubDate>Thu, 23 Jul 2026 21:06:08 GMT</pubDate><category>Zimbra</category><category>Russian Espionage</category><category>APT28</category><category>Zero-Day</category><category>Email Security</category></item><item><title>Zimbra Classic Web Client Stored XSS Leads to Session Hijacking</title><link>https://runtimerebel.com/blog/zimbra-classic-web-client-stored-xss-leads-to-session-hijacking</link><guid isPermaLink="true">https://runtimerebel.com/blog/zimbra-classic-web-client-stored-xss-leads-to-session-hijacking</guid><description>Zimbra warns of a critical stored XSS vulnerability in the Classic Web Client allowing attackers to execute malicious code via crafted emails.</description><pubDate>Sat, 11 Jul 2026 09:39:05 GMT</pubDate><category>Zimbra</category><category>Stored Xss</category><category>Webmail Security</category><category>Session Hijacking</category></item><item><title>Zimbra Classic Web Client XSS: Critical Flaw Under Active Exploit</title><link>https://runtimerebel.com/blog/zimbra-classic-web-client-xss-critical-flaw-under-active-exploit</link><guid isPermaLink="true">https://runtimerebel.com/blog/zimbra-classic-web-client-xss-critical-flaw-under-active-exploit</guid><description>A critical XSS vulnerability in Zimbra Classic Web Client is under active exploitation, allowing credential theft and session hijacking.</description><pubDate>Fri, 10 Jul 2026 14:31:43 GMT</pubDate><category>Zimbra</category><category>XSS</category><category>Classic Web Client</category><category>Zimbra Collaboration Suite</category><category>Active Exploitation</category></item><item><title>Zimbra XSS Attacks: Over 10,000 Servers Vulnerable — Patch Now</title><link>https://runtimerebel.com/blog/zimbra-xss-attacks-over-10000-servers-vulnerable-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/zimbra-xss-attacks-over-10000-servers-vulnerable-patch-now</guid><description>Ongoing cross-site scripting (XSS) attacks exploit a flaw in Zimbra Collaboration Suite (ZCS), leaving over 10,000 online servers vulnerable.</description><pubDate>Fri, 24 Apr 2026 16:28:18 GMT</pubDate><category>Zimbra</category><category>ZCS</category><category>XSS</category><category>Cross Site Scripting</category><category>Email Server</category><category>Vulnerability</category></item><item><title>CISA KEV Expansion: Exploit Guidance for Cisco, Kentico, and Zimbra</title><link>https://runtimerebel.com/blog/cisa-kev-expansion-exploit-guidance-for-cisco-kentico-and-zimbra</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisa-kev-expansion-exploit-guidance-for-cisco-kentico-and-zimbra</guid><description>CISA adds 8 vulnerabilities to the KEV catalog, including critical flaws in Cisco ASA and Zimbra. Analyze technical impact and remediation requirements.</description><pubDate>Tue, 21 Apr 2026 12:33:32 GMT</pubDate><category>CVE-2024-20481</category><category>CVE-2024-45519</category><category>CVE-2024-29847</category><category>Cisco</category><category>Zimbra</category><category>Ivanti</category></item><item><title>CISA KEV Update: Eight New Vulnerabilities in Cisco, TeamCity, and Zimbra</title><link>https://runtimerebel.com/blog/cisa-kev-update-eight-new-vulnerabilities-in-cisco-teamcity-and-zimbra</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisa-kev-update-eight-new-vulnerabilities-in-cisco-teamcity-and-zimbra</guid><description>CISA adds eight vulnerabilities to the KEV Catalog, including flaws in Cisco SD-WAN and JetBrains TeamCity, requiring immediate federal agency remediation.</description><pubDate>Tue, 21 Apr 2026 08:44:49 GMT</pubDate><category>CISA KEV</category><category>Cisco</category><category>TeamCity</category><category>CVE-2026-20122</category><category>PaperCut</category><category>Zimbra</category></item><item><title>APT28 Targets Ukraine via CVE-2024-45519 Zimbra Exploit</title><link>https://runtimerebel.com/blog/apt28-targets-ukraine-via-cve-2024-45519-zimbra-exploit</link><guid isPermaLink="true">https://runtimerebel.com/blog/apt28-targets-ukraine-via-cve-2024-45519-zimbra-exploit</guid><description>Russian APT28 hackers exploit CVE-2024-45519 in Zimbra Collaboration Suite to target Ukrainian government entities via malicious email-based command injection.</description><pubDate>Thu, 19 Mar 2026 16:25:10 GMT</pubDate><category>APT28</category><category>Zimbra</category><category>CVE-2024-45519</category><category>Ukraine</category><category>SSSCIP</category><category>GRU</category></item><item><title>CISA KEV Update: CVE-2025-66376 Zimbra and SharePoint Exploits</title><link>https://runtimerebel.com/blog/cisa-kev-update-cve-2025-66376-zimbra-and-sharepoint-exploits</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisa-kev-update-cve-2025-66376-zimbra-and-sharepoint-exploits</guid><description>CISA warns of active exploitation for Zimbra CVE-2025-66376, SharePoint flaws, and Cisco zero-days used in ransomware attacks. Secure your systems now.</description><pubDate>Thu, 19 Mar 2026 08:18:30 GMT</pubDate><category>CVE-2025-66376</category><category>Zimbra</category><category>SharePoint</category><category>CISA KEV</category><category>Cisco</category><category>Ransomware</category></item><item><title>CVE-2024-4510: Zimbra Collaboration Suite XSS Exploitation Guide</title><link>https://runtimerebel.com/blog/cve-2024-4510-zimbra-collaboration-suite-xss-exploitation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-4510-zimbra-collaboration-suite-xss-exploitation-guide</guid><description>CISA adds CVE-2024-4510 to the KEV catalog following active exploitation of a Zimbra Collaboration Suite XSS vulnerability. Patch ZCS version 9.0.0 today.</description><pubDate>Wed, 18 Mar 2026 20:16:14 GMT</pubDate><category>CVE-2024-4510</category><category>Zimbra</category><category>XSS</category><category>CISA KEV</category><category>Mail Security</category></item></channel></rss>