• About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us
TechTrendFeed
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT
No Result
View All Result
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT
No Result
View All Result
TechTrendFeed
No Result
View All Result

Zimbra CVE-2024-27443 XSS Flaw Hits 129K Servers, Sednit Suspected

Aarav Kapoor by Aarav Kapoor
May 24, 2025
Home Cybersecurity
Share on FacebookShare on Twitter


A important XSS vulnerability, CVE-2024-27443, in Zimbra Collaboration Suite’s CalendarInvite function is actively being exploited, doubtlessly by the Sednit hacking group. Learn the way this flaw permits attackers to compromise consumer periods and why instant patching is essential.

A brand new safety weak point has been found within the Zimbra Collaboration Suite (ZCS), a preferred e-mail and collaboration platform. This challenge, categorised as CVE-2024-27443, is a kind of cross-site scripting (XSS) flaw that would permit attackers to steal info or take management of consumer accounts.

How the Flaw Works

The issue lies particularly inside the CalendarInvite function of Zimbra’s Basic Internet Shopper interface. It occurs as a result of the system doesn’t correctly test incoming info within the Calendar header of emails.

This oversight creates a gap for a saved XSS assault. This implies an attacker can embed dangerous code right into a specifically designed e-mail. When a consumer opens this e-mail utilizing the basic Zimbra interface, the malicious code runs robotically inside their net browser, giving the attacker entry to their session. The severity of this vulnerability is rated as medium, with a CVSS rating of 6.1. It impacts ZCS variations 9.0 (patches 1-38) and 10.0 (as much as 10.0.6).

Widespread Publicity and Lively Exploitation

In accordance with Censys, a cybersecurity insights agency, as of Thursday, Could 22, 2025, when the unique report was revealed, a major variety of Zimbra Collaboration Suite cases had been uncovered on-line that may very well be weak.

Censys noticed a complete of 129,131 doubtlessly weak ZCS cases globally, with most present in North America, Europe, and Asia. A big majority of those are hosted inside cloud providers. Moreover, 33,614 on-premises Zimbra hosts had been recognized, typically linked to shared infrastructure.

The vulnerability was formally added to CISA’s Recognized Exploited Vulnerabilities (KEV) catalogue on Could 19, 2025, confirming it’s actively being utilized by attackers.

Potential Perpetrator?

Safety researchers from ESET have recommended {that a} well-known hacking group, Sednit (PDF) (AKA APT28 or Fancy Bear), could be concerned in exploiting it. ESET’s researchers suspect that the Sednit group may very well be exploiting this flaw as half of a bigger scheme known as Operation RoundPress, which goals to steal login particulars and preserve entry to webmail platforms. Whereas there may be at the moment no public proof-of-concept (PoC) exploit, the energetic exploitation highlights the urgency for customers to take motion.

Patching and Mitigation

The excellent news is that patches can be found for this vulnerability. Zimbra has addressed the difficulty in ZCS model 10.0.7 and 9.0.0 Patch 39. Customers are strongly suggested to replace their Zimbra Collaboration Suite to those patched variations instantly to guard towards potential assaults.



Tags: 129KCVE202427443FlawHitsSednitserversSuspectedXSSZimbra
Aarav Kapoor

Aarav Kapoor

Aarav Kapoor covers the latest in technology, gadgets, cybersecurity, software and smart home trends for TechTrendFeed. He breaks down complex tech news into clear, practical insights for everyday readers.

Next Post
Blue Prince Evaluate – GameSpot

Blue Prince Evaluate - GameSpot

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Trending.

Discover a Software program Improvement Firm in Europe

Discover a Software program Improvement Firm in Europe

August 22, 2025
Constructing cyber-resilient AI within the enterprise

Constructing cyber-resilient AI within the enterprise

September 14, 2026
The House Assistant survey dataset – Open House Basis

The House Assistant survey dataset – Open House Basis

August 29, 2026
KV Cache Administration: PagedAttention & RadixAttention

KV Cache Administration: PagedAttention & RadixAttention

August 23, 2026
Consider any agent framework with Amazon Bedrock AgentCore Evaluations

Consider any agent framework with Amazon Bedrock AgentCore Evaluations

August 27, 2026

TechTrendFeed

Welcome to TechTrendFeed, your go-to source for the latest news and insights from the world of technology. Our mission is to bring you the most relevant and up-to-date information on everything tech-related, from machine learning and artificial intelligence to cybersecurity, gaming, and the exciting world of smart home technology and IoT.

Categories

  • Cybersecurity
  • Gaming
  • Machine Learning
  • Smart Home & IoT
  • Software
  • Tech News

Recent News

Elevate Your Modern Home with LED Rose Lamps and West Elm Decor Ideas of 2026 – Chefio

Elevate Your Modern Home with LED Rose Lamps and West Elm Decor Ideas of 2026 – Chefio

September 16, 2026
Deltarune Creator Reveals The Worst Thing He’s Ever Made

Deltarune Creator Reveals The Worst Thing He’s Ever Made

September 16, 2026
  • About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us

© 2025 https://techtrendfeed.com/ - All Rights Reserved

No Result
View All Result
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT

© 2025 https://techtrendfeed.com/ - All Rights Reserved