When Business Email Compromise Starts Rewriting Reality
Rapid7, Wednesday, September 23rd, 2026
Rapid7 and Zimbra research found 50+ vulnerabilities letting attackers impersonate senders and rewrite inboxes without credentials.
Rapid7's collaborative research with Zimbra found more than 50 vulnerabilities in the Zimbra Collaboration Suite that go beyond the typical business email compromise model of silently monitoring a breached mailbox.
Several flaws let attackers actively rewrite environments, impersonating senders without credentials, controlling inbox visibility, and altering shared documents and calendars.
The piece cites prior exploited Zimbra CVEs added to CISA's Known Exploited Vulnerabilities catalog, including a 2024 postjournal command injection flaw and a 2025 stored XSS bug used as a zero-day against Brazilian military targets, with further technical detail promised in later installments.