ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Hackers actively exploiting five vulnerabilities in Zimbra Suite

The Cybersecurity and Infrastructure Security Agency (CISA) has released a new advisory warning of threat actors (TA) actively exploiting five vulnerabilities in the leading collaborative software suite Zimbra Collaboration, formerly known as the Zimbra Collaboration Suite (ZCS) that includes email, address book, calendaring, web documents, and file sharing.

 

The advisory was published in collaboration with the Multi-State Information Sharing & Analysis Center (MS-ISAC) and explains how threat actors may target unpatched ZCS instances in government and private sector networks.

 

According to the document, the first vulnerability is a high-severity flaw (CVE-2022-27924) that allows an unauthenticated threat actor to inject arbitrary memcache commands into a ZCS instance, leading to the overwriting of arbitrary cached entries. Then, without requiring user interaction, the actor can steal the cleartext password for the ZCS email account.

 

The second and third flaws mentioned in the document (CVE-2022-27925 and CVE-2022-37042, respectively) are chained together and allow an authenticated user to upload files to the system. In contrast, the third flaw allows for authentication to be bypassed.

 

The final two Zimbra flaws mentioned in the CISA report are UNIX CVE-2022-24682, a medium-severity flaw that affects ZCS webmail clients, and CVE-2022-30333, a high-severity directory traversal flaw in RARLAB UnRAR on Linux.

 

These flaws were reported to Zimbra, which fixed them all between May and July. Despite this, CISA advised administrators to look for malicious activity using the third-party detection signatures mentioned in the advisory, especially for companies that did not update their ZCS instances immediately.

 

The document also advised organizations to follow several best practices to lower the risk of compromises, such as keeping and testing an incident response plan, making sure they have a vulnerability management program, and properly configuring and securing network devices that are accessible via the internet, and implementing zero-trust principles and architecture.

 

CISA and the MS-ISAC stated that as new information becomes available, they would update the advisory to include additional indicators of compromise (IOCs) and signatures.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543