Zimbra releases an update patch to fix a critical vulnerability that allows hackers to execute malicious code without clicking.

Zimbra releases an update patch to fix a critical vulnerability that allows hackers to execute malicious code without clicking.

Information:

  Previously referred to as the Zimbra Collaboration Suite (ZCS), Zimbra is a comprehensive communication software solution that encompasses an email server and a web client. This suite offers a wide range of functionalities, including messaging, email, file sharing, calendar management, and task tracking.

Incident :

  Last week, Zimbra released patches for a critical stored cross-site scripting (XSS) security vulnerability affecting the Classic Web Client (Classic UI). This vulnerability could lead to code execution when opening an email.
  Zimbra stated that the update resolves a security issue in the Classic Web Client where a specially crafted email could execute malicious code upon opening. If exploited, this vulnerability could grant unauthorized access to mailbox information, session data, or account settings.
  Zimbra refrained from disclosing specific details about the flaw, which has not yet been assigned a CVE identifier. However, it strongly advised all customers utilizing the Classic Web Client to promptly update their deployments.

  The bug was resolved in Zimbra version 10.1.19, released on July 7. Customers upgrading from ZCS versions 10.0.x, 9.0.x, or 8.8.15 should update the SNMP mitigation and reapply it after the upgrade has been completed.
  Zimbra strongly recommends that all customers upgrade to ZCS v10.1.19 to ensure they have received the latest security patches, bug fixes, and enhancements.
  The vulnerability was reported by Google Threat Analysis Group (GTIG), which typically identifies security defects targeted by state-sponsored groups and commercial spyware vendors.

Recommendation :

  • Customers upgrading from ZCS 10.1.x: No additional action is required. If the SNMP mitigation has already been applied on your existing 10.1.x deployment, it will remain effective after upgrading to ZCS v10.1.19.
  • Customers upgrading from ZCS 10.0.x, 9.0.x, or 8.8.15: The SNMP mitigation must be updated and reapplied after upgrading to ZCS v10.1.19.

The important things is Security systems. We must concern and monitor as usual.
For more information please contact
Email :sales@inetms.co.th
065 149 2822 (Ms.Suphatson )
063 204 4534 (Ms.Atsamaphorn)
065 929 6330 (Ms.Kansinee)
092 257 6902 (Ms.Narusorn)
063 197 7510 (Mr.Yanotai)
065 725 7405 (Ms.Nattharini)
065 725 7405 (Ms.Donraya)

References :

Weekly Interesting CVE

NO.

CVE Name

Published Date

Last Update

Device/Appplication/OS Target

Attack Type

CVSS
Severity Rating

Detail

Solution

Reference

1

CVE-2026-48282

30/6/2026

7/7/2026

Adobe ColdFusion

Path Traversal

10

Through this vulnerability, a remote attacker can send a specially crafted request to perform a Path Traversal attack, bypassing restricted directories to read, write, or execute malicious scripts on the system. This leads to Remote Code Execution (RCE) within the context of the current user privileges, allowing the attacker to immediately compromise the organization's web serve

Update Adobe ColdFusion to the latest version

https://nvd.nist.gov/vuln/detail/CVE-2026-48282

2

CVE-2026-3829

7/7/2026

9/7/2026

Microsoft Outlook สำหรับ Windows (Microsoft 365 Apps)

Remote Code Execution (RCE) ผ่านระบบ Preview Pane

8.8

This vulnerability is triggered simply by opening the email or viewing it in the Preview Pane, which immediately executes the malicious code without requiring the user to open any attachments.

Update Microsoft Office / Outlook to the latest version

https://msrc.microsoft.com/update-guide/vulnerability

3

CVE-2026-2810

8/7/2026

12/7/2026

GitLab CE/EE เวอร์ชัน 16.x และ 17.x

Authentication Bypass

9.6

This vulnerability allows remote attackers to bypass login mechanisms and take over any GitLab user account—including Admin accounts—by sending specially crafted requests without a password

Update GitLab to the latest version

https://docs.gitlab.com/releases/ 

 4

CVE-2026-2041

8/7/2026

11/7/2026

Cisco Secure Client บน Windows และ macOS

Privilege Escalation

7.8

Low-privileged users or malware can exploit this vulnerability to achieve full Admin privileges and establish permanent persistence, making the system a high-value target for privilege escalation attacks

Update Cisco Secure Client to the latest version

https://nvd.nist.gov/vuln/detail/CVE-2023-20178

5

CVE-2026-3388

9/7/2026

13/7/2026

Apache Tomcat เวอร์ชัน 9.0.x, 10.1.x และ 11.0.x

Denial of Service (DoS)

7.5

Exploitation of this flaw can result in server unresponsiveness via resource exhaustion or trigger partial leaks of web application configuration data

Update version to 9.0.91, 10.1.25

https://httpd.apache.org/security/vulnerabilities_24.html

Malware News or Campaign IOC/IOA | EN

No

Campaign Name

Detection Date

Attack

Type

 

Description

 

Mitigation/Remediation

1

CAI cloud worm gives competitors' malware the boot, then steals secrets and mines for coin

07/07/2026​

Worm, ​

Cryptojacking,​

Backdoor 

Cybersecurity researchers from Hunt.io have exposed a new strain of malware called CAI (Cloud AI Infrastructure Attack Framework), a botnet targeting popular cloud-native tools such as Docker, Kubernetes, Redis, etcd, Kubelet, and Ray to steal credentials and mine cryptocurrency.What's notable is that CAI behaves like a "kill the competition first" operator, building on earlier malware such as TeamPCP and PCPJack, which previously wiped out each other's traces to seize control of victim machines. Researchers noted that CAI's codebase shows signs of AI-assisted development, suggesting its creator seriously studied rival techniques to build a more competitive tool.The attack begins with an automated scanning system that feeds targets into a centralized attack queue. Once a system is compromised, it installs a cryptocurrency miner, a credential stealer, and a Python backdoor on the victim's machine.Recent evidence confirms the attacks are still active, with cryptocurrency wallet activity indicating multiple successful compromises.​

  • Restrict/Disable Public-Facing API Access​
  • Enforce Authentication and RBAC Across All Services​
  • Apply Security Patches Consistently​

Ref: https://www.theregister.com/cyber-crime/2026/07/07/cai-cloud-worm-gives-competitors-malware-the-boot-then-steals-secrets-and-mines-for-coin/5267856 

22 July 2026

Viewed 86 time

Engine by shopup.com