Zimbra releases an update patch to fix a critical vulnerability that allows hackers to execute malicious code without clicking.

Information:
Previously referred to as the Zimbra Collaboration Suite (ZCS), Zimbra is a comprehensive communication software solution that encompasses an email server and a web client. This suite offers a wide range of functionalities, including messaging, email, file sharing, calendar management, and task tracking.
Incident :
Last week, Zimbra released patches for a critical stored cross-site scripting (XSS) security vulnerability affecting the Classic Web Client (Classic UI). This vulnerability could lead to code execution when opening an email.
Zimbra stated that the update resolves a security issue in the Classic Web Client where a specially crafted email could execute malicious code upon opening. If exploited, this vulnerability could grant unauthorized access to mailbox information, session data, or account settings.
Zimbra refrained from disclosing specific details about the flaw, which has not yet been assigned a CVE identifier. However, it strongly advised all customers utilizing the Classic Web Client to promptly update their deployments.
The bug was resolved in Zimbra version 10.1.19, released on July 7. Customers upgrading from ZCS versions 10.0.x, 9.0.x, or 8.8.15 should update the SNMP mitigation and reapply it after the upgrade has been completed.
Zimbra strongly recommends that all customers upgrade to ZCS v10.1.19 to ensure they have received the latest security patches, bug fixes, and enhancements.
The vulnerability was reported by Google Threat Analysis Group (GTIG), which typically identifies security defects targeted by state-sponsored groups and commercial spyware vendors.
Recommendation :
The important things is Security systems. We must concern and monitor as usual.
For more information please contact
Email :sales@inetms.co.th
065 149 2822 (Ms.Suphatson )
063 204 4534 (Ms.Atsamaphorn)
065 929 6330 (Ms.Kansinee)
092 257 6902 (Ms.Narusorn)
063 197 7510 (Mr.Yanotai)
065 725 7405 (Ms.Nattharini)
065 725 7405 (Ms.Donraya)
References :
Weekly Interesting CVE
| NO. |
CVE Name |
Published Date |
Last Update |
Device/Appplication/OS Target |
Attack Type |
CVSS |
Detail |
Solution |
Reference |
|---|---|---|---|---|---|---|---|---|---|
| 1 |
CVE-2026-48282 |
30/6/2026 |
7/7/2026 |
Adobe ColdFusion |
Path Traversal |
10 |
Through this vulnerability, a remote attacker can send a specially crafted request to perform a Path Traversal attack, bypassing restricted directories to read, write, or execute malicious scripts on the system. This leads to Remote Code Execution (RCE) within the context of the current user privileges, allowing the attacker to immediately compromise the organization's web serve |
Update Adobe ColdFusion to the latest version |
|
| 2 |
CVE-2026-3829 |
7/7/2026 |
9/7/2026 |
Microsoft Outlook สำหรับ Windows (Microsoft 365 Apps) |
Remote Code Execution (RCE) ผ่านระบบ Preview Pane |
8.8 |
This vulnerability is triggered simply by opening the email or viewing it in the Preview Pane, which immediately executes the malicious code without requiring the user to open any attachments. |
Update Microsoft Office / Outlook to the latest version |
|
| 3 |
CVE-2026-2810 |
8/7/2026 |
12/7/2026 |
GitLab CE/EE เวอร์ชัน 16.x และ 17.x |
Authentication Bypass |
9.6 |
This vulnerability allows remote attackers to bypass login mechanisms and take over any GitLab user account—including Admin accounts—by sending specially crafted requests without a password |
Update GitLab to the latest version |
|
| 4 |
CVE-2026-2041 |
8/7/2026 |
11/7/2026 |
Cisco Secure Client บน Windows และ macOS |
Privilege Escalation |
7.8 |
Low-privileged users or malware can exploit this vulnerability to achieve full Admin privileges and establish permanent persistence, making the system a high-value target for privilege escalation attacks |
Update Cisco Secure Client to the latest version |
|
| 5 |
CVE-2026-3388 |
9/7/2026 |
13/7/2026 |
Apache Tomcat เวอร์ชัน 9.0.x, 10.1.x และ 11.0.x |
Denial of Service (DoS) |
7.5 |
Exploitation of this flaw can result in server unresponsiveness via resource exhaustion or trigger partial leaks of web application configuration data |
Update version to 9.0.91, 10.1.25 |
Malware News or Campaign IOC/IOA | EN
|
No |
Campaign Name |
Detection Date |
Attack Type |
Description |
Mitigation/Remediation |
|---|---|---|---|---|---|
| 1 |
CAI cloud worm gives competitors' malware the boot, then steals secrets and mines for coin |
07/07/2026 |
Worm, Cryptojacking, Backdoor |
Cybersecurity researchers from Hunt.io have exposed a new strain of malware called CAI (Cloud AI Infrastructure Attack Framework), a botnet targeting popular cloud-native tools such as Docker, Kubernetes, Redis, etcd, Kubelet, and Ray to steal credentials and mine cryptocurrency.What's notable is that CAI behaves like a "kill the competition first" operator, building on earlier malware such as TeamPCP and PCPJack, which previously wiped out each other's traces to seize control of victim machines. Researchers noted that CAI's codebase shows signs of AI-assisted development, suggesting its creator seriously studied rival techniques to build a more competitive tool.The attack begins with an automated scanning system that feeds targets into a centralized attack queue. Once a system is compromised, it installs a cryptocurrency miner, a credential stealer, and a Python backdoor on the victim's machine.Recent evidence confirms the attacks are still active, with cryptocurrency wallet activity indicating multiple successful compromises. |
|
22 July 2026
Viewed 86 time