Vulnerabilities uncovered in the Rapid7-Zimbra research: 50+ (Source: Rapid7 blog, joint research with Zimbra (September 27, 2026))
A Different Kind of Mailbox Breach
Business Email Compromise has followed a familiar script for years: an attacker gets into a mailbox, watches quietly, learns who approves what, then strikes. Collaborative research between Rapid7 and Zimbra, published September 27, 2026, describes something different inside the Zimbra Collaboration Suite: vulnerabilities that let an attacker write to email, shared documents, and calendars, not just read them, without ever obtaining a password.
The researchers found that several of these flaws let an attacker impersonate a sender, control what appears in an inbox, and alter shared documents or calendar entries. Send a message as the CFO without touching their password, and an attacker has built the front half of a convincing fraud. Keep control of the mailbox afterward, and the back half follows: the attacker can delete the sent item to erase the trail, or leave it in place so the CFO sees 'evidence' of a message they never sent.
A Documented Pattern, Not a One-Off
Zimbra's appearance in CISA's Known Exploited Vulnerabilities catalog spans three consecutive years, according to Rapid7. CVE-2024-45519, an unauthenticated command injection in the postjournal service, was exploited by attackers stuffing base64 payloads into CC fields; Proofpoint observed this on September 28, 2024, and CISA added it to KEV five days later. CVE-2025-27915, a stored XSS delivered through a crafted calendar attachment, was used as a zero-day against Brazilian military targets to steal mail and quietly set forwarding filters, entering KEV in October 2025. Most recently, CVE-2026-73570, an unauthenticated command injection through SNMP notification handling, was added to KEV on August 21, 2026.
When the System of Record Lies
Rapid7 describes a scenario it calls 'calendar warfare': meetings modified or deleted without the notification trail users expect, RSVP status flipped from Accepted to Declined, or a fabricated 'Emergency Board Meeting' placed on an executive's calendar with a believable organizer and a malicious link. Stack a fake HR memo, a follow-up email from a trusted colleague referencing it, and a calendar invite to discuss it, and each artifact props up the others — all generated inside a system the victim has no reason to distrust. CVE-2025-27915 was delivered the same way, through a calendar invite.
Not an Isolated Incident
Zimbra's exploitation history runs further back. Rapid7 tracked widespread exploitation of CVE-2022-27925 and CVE-2022-37042, a path traversal chained with an authentication bypass that let attackers drop a web shell without credentials. Google's Threat Analysis Group later found the same zero-day, tracked as CVE-2023-37580, being worked by multiple threat groups going after email, credentials, and authentication tokens.
What a Budget Holder Should Ask
For organizations running Zimbra Collaboration Suite, this research reframes BEC as a data-integrity problem, not just a data-theft one. Ask your team which Zimbra version is deployed and whether it addresses CVE-2026-73570. Ask whether the incident response plan treats calendar and document tampering as a distinct scenario from credential theft, with its own verification steps. And ask what happens procedurally when Finance sees a sent request that the named sender says they never sent — who adjudicates, and what evidence outside the mail system itself is used to settle it.





