<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

CISA Warns Federal Agencies of Actively Exploited Zimbra Email Vulnerability

CISA urges agencies to patch critical Zimbra flaw CVE-2025-68645, exploited by attackers, to prevent unauthorized access and data exposure.
Content Team

CISA added a critical Zimbra Collaboration Suite vulnerability to its Known Exploited Vulnerabilities catalog Thursday, urging federal agencies to patch immediately. The flaw (CVE-2025-68645) allows attackers to access sensitive files without authentication by exploiting the webmail interface's RestFilter servlet.

Threat actors are already using this vulnerability in sophisticated, targeted campaigns according to CrowdSec researchers. The bug can expose internal system information and enable further attacks when combined with other weaknesses.

Zimbra released patches in November 2025 for versions 10.1.13 and 10.0.18. Federal agencies have three weeks to fix this and three other newly identified exploited vulnerabilities under government security directives.

Source: Security Week

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo