
Critical Zimbra RCE Vulnerability Actively Exploited in Attacks
CERT Polska reported that attackers are actively exploiting a critical remote code execution (RCE) vulnerability in Zimbra Collaboration Suite (ZCS). The flaw, identified as CVE-2024-45519, allows unauthenticated threat actors to execute arbitrary code on vulnerable Zimbra email servers. No specific dates for the exploitation onset were provided, but the warning confirms ongoing attacks targeting unpatched systems. The vulnerability affects Zimbra versions prior to the latest security updates, though exact version ranges were not disclosed. Successful exploitation could lead to full system compromise, including unauthorized access to sensitive email data. Organizations using ZCS are advised to apply patches immediately, though no mitigation steps were detailed in the notice.