Malicious actors appear to have discovered and are actively exploiting a zero-day vulnerability in Zimbra to launch attacks on European media and government organizations.

See also: Apple fixes zero-day bugs affecting iOS/macOS devices
Zimbra is an email platform that also includes instant messaging, contacts, video conferencing, file sharing, and cloud storage capabilities.
According to Zimbra, more than 200,000 businesses from over 140 countries use its software, including over 1,000 government and financial organizations.
"This exploit does not have any patch available, nor has it been assigned a CVE, making it a zero-day vulnerability," the researchers said.
“Volexity can confirm and has tested that the latest versions of Zimbra—8.8.15 P29 & P30—remain vulnerable. Testing of version 9.0.0 indicates that it is likely not affected.“
Volexity says that so far, it has only observed a single malicious actor known as TEMP_Heretic, likely from China, that exploits the zero-day in spear-phishing to steal emails.
See also: Windows: Zero-day “RemotePotato0” receives unofficial update
However, the vulnerability could also allow attackers to perform other malicious actions “within the context of the user’s Zimbra email session,” such as:
- Export cookies to allow permanent access to a mailbox
- Sending phishing messages to the user's contacts
- Prompting to download malware from seemingly trustworthy websites

Since the exploit was launched in December, Volexity has seen TEMP_Heretic checking for live email addresses, using email IDs with embedded remote images.
In the next stage of the attack, malicious users sent spear-phishing emails with malicious links and various subjects (e.g., interview requests, invitations to charity auctions, and holiday wishes) in multiple waves between mid-December 2021.
“By clicking on the malicious link, the attacker’s infrastructure will attempt a redirect to a page on the targeted organization’s Zimbra email server, with a specific URI format which—if the user is logged in—exploits a vulnerability that allows arbitrary JavaScript to be loaded within a logged-in Zimbra session,” the researchers added.
The malicious code allows attackers to sneak through emails into victims' mailboxes and infiltrate email content and attachments on servers controlled by the attackers.
See also: Diavol ransomware spreads via email and steals money
Volexity recommends taking the following measures to block attacks that exploit this vulnerability:
- All indications here should be blocked at the mail gateway and network level.
- Zimbra users should analyze referral data for suspicious access and referrals.
- Zimbra users should consider upgrading to version 9.0.0, as there is currently no secure version of 8.8.15.
