Google's Threat Analysis Group has identified four separate campaigns targeting the Zimbra Collaboration vulnerability (CVE-2023-37580) in recent months.
A newly identified phishing campaign is targeting Zimbra Collaboration users around the world.
The Zimbra Collaboration Suite version 8.8.15 has a cross-site scripting flaw that Google researchers say has been actively exploited.
Zimbra has published mitigations against the actively exploited flaw (CVE-2022-41352) in Zimbra Collaboration Suite; however, it has yet to issue a fix.