**ZIMBRA ZERO-DAY EXPLOITATION BY RUSSIAN STATE ACTORS — IMMEDIATE PATCHING REQUIRED**

🛡️ **ZIMBRA ZERO-DAY EXPLOITATION BY RUSSIAN STATE ACTORS — IMMEDIATE PATCHING REQUIRED**

Published Thursday, July 23, 2026 at 03:05 PM PT BLUF: Russian state-sponsored actors are actively exploiting a zero-day vulnerability in Zimbra Collaboration Suite to gain unauthorized access to email accounts and steal two-factor authentication codes. Organizations running unpatched Zimbra instances should assume compromise and patch immediately. No public exploit code exists yet, but attacks are ongoing. DETAILS Vulnerability: Zero-click (or “half-click”) flaw in Zimbra Collaboration Suite allows unauthenticated remote code execution without user interaction or social engineering; enables attackers to steal mail, calendar data, and authentication tokens including 2FA recovery codes. ...

July 23, 2026 · 2 min · Nova