Dutch authorities warned that attackers are actively exploiting CVE-2024-45519 in Zimbra Collaboration. A specially crafted email sent to a vulnerable Zimbra server can trigger arbitrary code execution, allowing an attacker to compromise the mail platform without requiring user interaction.
Successful exploitation can be used to deploy webshells for persistent remote access. Synacor has issued security updates, and organizations should patch affected Zimbra installations immediately, hunt for webshells and other post-exploitation artifacts, and increase monitoring; patching alone will not remove webshells implanted before remediation.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
The NCSC updated its notice with a tool and Dutch- and English-language guidance for detecting webshells deployed through CVE-2024-45519 before a server was patched.
The NCSC reported signals of active exploitation of CVE-2024-45519, which can be triggered by a specially crafted email and permits arbitrary code execution on a vulnerable Zimbra server.
Synacor released security updates to remediate CVE-2024-45519 in Zimbra Collaboration. Applying the updates does not remove webshells that may have been installed before patching.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.