TL;DR: Russian actors tracked as Laundry Bear are exploiting an unpatched Zimbra zero-day to steal email from US and Ukraine targets, while CISA KEV and trusted press reporting also highlight urgent risks in ColdFusion, SharePoint, Exchange, and other exploited flaws. The operative issue is not vulnerability volume but exposure management, because standing internet-facing services turn patch delay into active compromise.
NHIMG editorial — based on content published by Senserva: Russian hackers exploit an unpatched Zimbra zero-day and related exploited CVEs
By the numbers:
- 85% of organisations lack full visibility into third-party vendors connected via OAuth apps , 38% have no or low visibility, and a further 47% have only partial visibility.
Questions worth separating out
Q: What breaks when an internet-facing mail server is exploited before patching?
A: The breach is rarely limited to a single mailbox.
Q: Why do email platforms create such high identity risk during active exploitation?
A: Email platforms sit inside account recovery and approval workflows, so compromise can expose credentials, session tokens, and security notifications.
Q: How do teams know whether accepted vulnerabilities are truly under control?
A: An accepted vulnerability is under control only when the exception is documented, the compensating control is real, and the review date is enforced.
Practitioner guidance
- Prioritise exploited mail and collaboration systems Move Zimbra, ColdFusion, SharePoint, and Exchange items flagged as actively exploited to the front of the remediation queue, even if they are outside the normal change window.
- Hunt for mailbox persistence indicators Review forwarding rules, inbox filters, delegated access, and unusual OAuth connections after patching any compromised mail service.
- Tighten identity recovery controls Validate that password reset flows, admin approvals, and mailbox-based recovery paths cannot be abused by an attacker who has read access to email.
What's in the full analysis
Senserva's full article covers the operational detail this post intentionally leaves for the source:
- Daily-exploited CVE tracking across Zimbra, ColdFusion, SharePoint, Exchange, and other KEV-listed services.
- The source's ranked patch tracker logic using CISA KEV, EPSS, and ransomware linkage for decision-making.
- The non-Microsoft exploited-CVE tracker that follows daily KEV additions for fast triage.
- Free unlimited audits for Microsoft 365, Intune, Defender, and Entra ID posture after one-time registration.
👉 Read Senserva's analysis of active Zimbra exploitation and KEV patch triage →
Zimbra zero-day exploitation and KEV patch triage: what now?
Explore further
Exploitability now outweighs technical novelty in patch governance. The market still talks about zero-days as exceptional events, but defenders are dealing with a repeatable operational pattern: exposed services, public exploit reporting, and a short window before abuse spreads. For identity teams, that means mail and collaboration platforms must be treated as high-risk access surfaces, not just application uptime dependencies. The practitioner conclusion is simple: exploit status should reshape control priority immediately.
A question worth separating out:
Q: Which frameworks should organisations use to prioritise active exploitation and access abuse?
A: Use NIST CSF for exposure management and response, NIST SP 800-53 for access and audit controls, and MITRE ATT&CK to map exploit, credential access, and impact stages. If email or identity workflows are involved, include identity governance in the same review.
👉 Read our full editorial: Active exploitation of Zimbra and KEV flaws is driving patch priority