<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>0dayNews — Zimbra</title><description>Vulnerabilities, patches, and vendor advisories affecting Zimbra Collaboration Suite — the Classic Web Client, Modern UI, and mailboxd server components — plus the operational impact of Zimbra patch cycles on the organizations still self-hosting webmail. Combined article + CVE feed for the Zimbra beat.</description><link>https://0daynews.com/</link><language>en-us</language><item><title>270 Zimbra Servers Breached as KEV Deadline Expires</title><link>https://0daynews.com/articles/2026-08-25-zimbra-270-servers-breached-kev-deadline/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-25-zimbra-270-servers-breached-kev-deadline/</guid><description>Attackers have compromised 270+ Zimbra ZCS servers via CVE-2026-73570 SNMP RCE. CISA&apos;s Aug 24 KEV patch deadline is past; upgrade to ZCS 10.1.20 now.</description><pubDate>Tue, 25 Aug 2026 14:00:00 GMT</pubDate><category>Zimbra</category><category>article</category></item><item><title>Zimbra SNMP RCE Now Exploited in the Wild</title><link>https://0daynews.com/articles/2026-08-21-zimbra-snmp-rce-exploited/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-21-zimbra-snmp-rce-exploited/</guid><description>CVE-2026-73570, a CVSS 8.9 command injection in Zimbra ZCS, is under active exploitation per CERT Polska. Patch to 10.1.20 or later immediately.</description><pubDate>Fri, 21 Aug 2026 02:00:00 GMT</pubDate><category>Zimbra</category><category>article</category></item><item><title>Void Blizzard Exploits Zimbra Flaw for Email Theft</title><link>https://0daynews.com/articles/2026-07-23-void-blizzard-zimbra-zero-click-email-theft-airgap/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-23-void-blizzard-zimbra-zero-click-email-theft-airgap/</guid><description>CISA warns Russian state-sponsored Void Blizzard (Laundry Bear) is combining phishing with a patched Zimbra zero-click flaw to steal email from targeted organizations.</description><pubDate>Thu, 23 Jul 2026 18:00:00 GMT</pubDate><category>Zimbra</category><category>article</category></item><item><title>Zimbra 10.1.20 patches nine, SNMP injection at the top</title><link>https://0daynews.com/articles/2026-07-21-zimbra-10-1-20-nine-bugs-snmp-command-injection-tops-list/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-21-zimbra-10-1-20-nine-bugs-snmp-command-injection-tops-list/</guid><description>Zimbra 10.1.20 fixes nine vulnerabilities including an SNMP command injection when notifications are enabled. Patch if you self-host — CVEs pending.</description><pubDate>Tue, 21 Jul 2026 23:45:00 GMT</pubDate><category>Zimbra</category><category>article</category></item><item><title>Zimbra ships 10.1.19; Google TAG reported the XSS</title><link>https://0daynews.com/articles/2026-07-11-zimbra-10-1-19-classic-web-client-xss-google-tag/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-11-zimbra-10-1-19-classic-web-client-xss-google-tag/</guid><description>Zimbra 10.1.19 patches a stored XSS in the Classic Web Client. No CVE yet, no confirmed exploitation — Google TAG reported it, which is the reason to patch now.</description><pubDate>Sat, 11 Jul 2026 02:15:00 GMT</pubDate><category>Zimbra</category><category>article</category></item></channel></rss>