A Russian-based threat group Winter Vivern or TA473 has been targeting a flaw in the Zimbra webmail client to exfiltrate emails from officials in European countries.
Security outfit Proofpoint said the attackers exploit a vulnerability tracked as CVE-2022-27926 on unpatched internet-facing Zimbra Collaboration servers, which it discovered using a vulnerability scanner.
CVE-2022-27926 is described as a “Reflected cross-site scripting (XSS) vulnerability of Zimbra Collaboration 9.0” that “allows unauthenticated attackers to execute arbitrary web script or HTML via request parameters.” It was patched by Zimbra in April 2022.