CVE-2025-71275Disclosure

LOW

Exploit discussion active in current signal (6 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Rejected reason: This CVE was rejected due to being a duplicate of CVE-2024-45519.

2.0/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • 6 total mentions across 1 day

Deep dive

Activity timeline6 mentions / 1d
02356Mentions · 2026-03-24: 6PoC Mentioned / Linked · 2026-03-24: 1Patch / Workaround · 2026-03-24: 2Technical Details · 2026-03-24: 603-24
Signal classification2 categories
Disclosure
466.7%
Patch
233.3%
Referenced assets8 URLs
Full discourse6 posts
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2025-71275 — CVSS 9.8/10 ██████████ Zimbra Collaboration Suite (ZCS) PostJournal service version 8.8.15 contains a command injection vulnerability that... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/KwBKPudqcQ

    Post summary

    A critical command injection vulnerability (CVE-2025-71275) in Zimbra Collaboration Suite is confirmed, with a patch now available.

    10000179
    9 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2025-71275 - Critical Zimbra Collaboration Suite (ZCS) PostJournal service version 8.8.15 contains a command injection vulnerability that allows unauthenticated attackers to execute arbitrary system commands b... https://www.thehackerwire.com/vulnerability/CVE-2025-71275/ https://t.co/DFyPMVmFkL

    Post summary

    A command injection vulnerability (CVE-2025-71275) affecting Zimbra Collaboration Suite 8.8.15 has been disclosed, detailing unauthenticated execution of arbitrary system commands, but no PoC, exploit, patch, or active exploitation information is provided.

    00000183
    145 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-71275 Zimbra Collaboration Suite (ZCS) PostJournal service version 8.8.15 contains a command injection vulnerability that allows unauthenticated attackers to execute arbitr… https://www.cve.org/CVERecord?id=CVE-2025-71275

    Post summary

    The text announces that CVE‑2025‑71275 is a command injection flaw in Zimbra Collaboration Suite’s PostJournal service, permitting unauthenticated arbitrary command execution, but provides no PoC, exploit, active use, or patch information.

    00000134
    56.8K followersView on X
  • dbugs@ptdbugs
    Disclosure

    Zimbra Collaboration Suite PostJournal 8.8.15 Unauthenticated Remote Code Execution via SMTP Injection CVE: CVE-2025-71275 PT-Identifier: PT-2026-27441 Vendor: Zimbra Product: Zimbra Collaboration Suite CVSS: 9.3 Credits: indoushka Description: A critical security vulnerability exists in Zimbra Collaboration Suite (ZCS) PostJournal service version 8.8.15 that allows unauthenticated attackers to execute arbitrary system commands via SMTP injection. The vulnerability is triggered through improper sanitization of the RCPT TO parameter, enabling command injection using shell expansion syntax (e.g., $(COMMAND)). Successful exploitation results in remote code execution under the Zimbra service context without requiring authentication. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2025-71275 • https://packetstorm.news/files/id/212108/ • https://www.zimbra.com/ • https://www.vulncheck.com/advisories/zimbra-collaboration-suite-postjournal-unauthenticated-remote-code-execution-via-smtp-injection #dbugs_vuln

    Post summary

    The advisory announces a critical unauthenticated remote code execution flaw in Zimbra Collaboration Suite’s PostJournal service, providing detailed technical information and a PoC reference but no patch or evidence of active exploitation.

    00000292
    746 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2025-71275: CRITICAL] Critical vulnerability in Zimbra Collaboration Suite (ZCS) 8.8.15 PostJournal service enables attackers to run commands remotely. Ensure immediate patching to safeguard against exp...#cve,CVE-2025-71275,#cybersecurity https://cvefind.com/CVE-2025-71275

    Post summary

    The tweet warns about a critical remote command execution vulnerability in Zimbra and urges users to apply the available patch immediately.

    0000099
    606 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2025-71275: Zim... Shell expansion in SMTP RCPT TO params = instant RCE on every Zimbra 8.8.15 box exposed to mail traffic - no auth needed. #ZimbraRCE #SMTPInjection. https://zerodaysignal.com/vulnerability/CVE-2025-71275 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE-2025-71275, a shell‑expansion flaw in Zimbra 8.8.15 that permits unauthenticated, instant RCE via SMTP RCPT TO parameters, and links to a vulnerability summary.

    00000217
    164 followersView on X

Explore more