Skip to content
Security & Trust

Zimbra Flaws Let Attackers Rewrite Email, Not Just Read It

Rapid7 and Zimbra found 50+ flaws letting attackers impersonate executives and edit shared records without credentials.

K
Kannan SP
· 5 min read
Share on X LinkedIn
Zimbra Flaws Let Attackers Rewrite Email, Not Just Read It
Key finding

Vulnerabilities uncovered in the Rapid7-Zimbra research: 50+ (Source: Rapid7 blog, joint research with Zimbra (September 27, 2026))

A Different Kind of Mailbox Breach

Business Email Compromise has followed a familiar script for years: an attacker gets into a mailbox, watches quietly, learns who approves what, then strikes. Collaborative research between Rapid7 and Zimbra, published September 27, 2026, describes something different inside the Zimbra Collaboration Suite: vulnerabilities that let an attacker write to email, shared documents, and calendars, not just read them, without ever obtaining a password.

50+
Vulnerabilities uncovered in the Rapid7-Zimbra research
Source: Rapid7 blog, joint research with Zimbra (September 27, 2026)

The researchers found that several of these flaws let an attacker impersonate a sender, control what appears in an inbox, and alter shared documents or calendar entries. Send a message as the CFO without touching their password, and an attacker has built the front half of a convincing fraud. Keep control of the mailbox afterward, and the back half follows: the attacker can delete the sent item to erase the trail, or leave it in place so the CFO sees 'evidence' of a message they never sent.

A Documented Pattern, Not a One-Off

Zimbra's appearance in CISA's Known Exploited Vulnerabilities catalog spans three consecutive years, according to Rapid7. CVE-2024-45519, an unauthenticated command injection in the postjournal service, was exploited by attackers stuffing base64 payloads into CC fields; Proofpoint observed this on September 28, 2024, and CISA added it to KEV five days later. CVE-2025-27915, a stored XSS delivered through a crafted calendar attachment, was used as a zero-day against Brazilian military targets to steal mail and quietly set forwarding filters, entering KEV in October 2025. Most recently, CVE-2026-73570, an unauthenticated command injection through SNMP notification handling, was added to KEV on August 21, 2026.

260+
Compromised instances tied to CVE-2026-73570
Source: Shadowserver, cited in Rapid7 blog (September 2026)
3 days
Federal remediation window CISA set for CVE-2026-73570
Source: CISA KEV catalog addition, August 21, 2026 (BOD 22-01 applies to federal agencies only)

When the System of Record Lies

Rapid7 describes a scenario it calls 'calendar warfare': meetings modified or deleted without the notification trail users expect, RSVP status flipped from Accepted to Declined, or a fabricated 'Emergency Board Meeting' placed on an executive's calendar with a believable organizer and a malicious link. Stack a fake HR memo, a follow-up email from a trusted colleague referencing it, and a calendar invite to discuss it, and each artifact props up the others — all generated inside a system the victim has no reason to distrust. CVE-2025-27915 was delivered the same way, through a calendar invite.

Not an Isolated Incident

Zimbra's exploitation history runs further back. Rapid7 tracked widespread exploitation of CVE-2022-27925 and CVE-2022-37042, a path traversal chained with an authentication bypass that let attackers drop a web shell without credentials. Google's Threat Analysis Group later found the same zero-day, tracked as CVE-2023-37580, being worked by multiple threat groups going after email, credentials, and authentication tokens.

4
Distinct threat groups documented exploiting CVE-2023-37580
Source: Google Threat Analysis Group, cited in Rapid7 blog (September 2026)

What a Budget Holder Should Ask

For organizations running Zimbra Collaboration Suite, this research reframes BEC as a data-integrity problem, not just a data-theft one. Ask your team which Zimbra version is deployed and whether it addresses CVE-2026-73570. Ask whether the incident response plan treats calendar and document tampering as a distinct scenario from credential theft, with its own verification steps. And ask what happens procedurally when Finance sees a sent request that the named sender says they never sent — who adjudicates, and what evidence outside the mail system itself is used to settle it.

Share this insight