⚡ Get unlimited AI threat intel — exploit-db.ai →
CRITICAL

CVE-2019-9670

⚡ Llama-3 AI Analysis

Executive Briefing

Zimbra XXE enabling SSRF and file read — exploited to steal admin credentials and access internal services. Apply Zimbra patches immediately. Disable XML external entity processing in Zimbra mailboxd. Monitor for unusual outbound HTTP from mail servers.

NVD Description

Synacor Zimbra Collaboration Suite before 8.7.12 has an XXE vulnerability in XML processing in the mailboxd component, which can be used to obtain SSRF and arbitrary file reads.

Want alerts for CVEs like this?

Exploit-DB.ai delivers real-time AI-triaged zero-day alerts directly to your inbox.

Activate Supernova →

Official Sources