Zimbra has released software updates to address vulnerabilities in its Collaboration software.

The first vulnerability is tracked as CVE-2025-25064 and is considered critical, with a CVSS score of 9.8/10.0. It is a SQL injection vulnerability located in the ZimbraSync Service SOAP endpoint and affects versions prior to 10.0.12 and 10.1.4.
This vulnerability could be exploited by authorized attackers to inject arbitrary SQL queries that could retrieve email metadata “using a specific parameter in the request.”
See also: Hackers exploit vulnerabilities in SimpleHelp RMM
Zimbra has also fixed a second critical vulnerability related to stored cross-site scripting (XSS) in the Zimbra Classic Web Client. The company has fixed the issue in versions 9.0.0 Patch 44, 10.0.13, and 10.1.5.
Finally, another, less critical vulnerability (CVSS score: 5.3) has been fixed. It is tracked as CVE-2025-25065 and is located in the RSS feed parser component, allowing unauthorized redirection to internal network endpoints. The vulnerability has been fixed in versions 9.0.0 Patch 43, 10.0.12, and 10.1.4. Customers are advised to apply the latest versions of Zimbra Collaboration as soon as possible.
See also: Critical Microsoft Outlook vulnerability used in attacks
To further enhance the security of their systems, organizations can also consider implementing additional measures such as network segmentation, strict access controls, and regular security audits.

Additionally, it is important to train employees in basic cybersecurity practices, such as creating strong passwords, avoiding suspicious emails or links, and regularly backing up important data. Additionally, conducting thorough background checks on employees with access to sensitive information can help deter insider threats.
See also: Multiple vulnerabilities in Cisco SNMP allow DoS attacks
In addition to technical measures, a company's overall security posture also depends on its incident response plan. It is important for organizations to have a well-defined plan that outlines the steps to be taken in the event of a security breach. It is also recommended to regularly test and update this plan.
Source: thehackernews.com
