A view-triggered flaw in Zimbra Collaboration Suite shows how one vulnerable inbox interface can put mail history, credentials, and internal directories within reach of a determined operator.
A zero-day in Zimbra Classic UI let a malicious message run code inside the webmail session, shifting the attack goal from inbox access to broader account and identity theft.
CISA and partner agencies say a Russian state-supported campaign is using a Zimbra flaw to pull mail, directory data, and account material from exposed webmail users.