A view-triggered flaw in Zimbra Collaboration Suite shows how one vulnerable inbox interface can put mail history, credentials, and internal directories within reach of a determined operator.
A Zimbra webmail flaw turned a normal open or preview action into a route for credential theft and message harvesting, showing how a trusted inbox can become the first foothold.
A zero-day in Zimbra Classic UI let a malicious message run code inside the webmail session, shifting the attack goal from inbox access to broader account and identity theft.
A phishing campaign tied to a Zimbra zero-day shows how one compromised webmail layer can put months of correspondence and sensitive material at risk.