Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
Rapid7 has disclosed collaborative research with Zimbra exposing over 50 vulnerabilities in the Collaboration Suite, some allowing attackers to impersonate senders without credentials, manipulate calendars, and alter shared documents. The discovery shifts Business Email Compromise from financial fraud to an operation that manipulates shared perception, with implications extending beyond the IT department.
The analysis, published September 23, 2026, documents a paradigm shift: attackers are no longer limited to stealing money or data but can engineer "manufactured enterprise reality" — corporate reality fabricated by design. The platform becomes a tool for organizational gaslighting, where deleted emails, moved meetings, and altered documents generate irreconcilable evidence conflicts that traditional procedures cannot resolve.
- Rapid7 discovered over 50 vulnerabilities in Zimbra Collaboration Suite, some impacting authentication, calendars, and document sharing.
- Attackers can send email as executives without passwords, then choose whether to delete the message or leave it — creating corporate gaslighting scenarios.
- Calendar manipulation ("calendar warfare") enables creation of fake meetings with malicious links that appear legitimate because they have been present for days.
- CISA confirms Russian APT LAUNDRY BEAR has exploited Zimbra since July 2025 using view-based exploits, exfiltrating email and 2FA tokens for approximately 90 days.
How Evolved BEC Attacks the "System of Record"
The core mechanism documented by Rapid7 is the abuse of collaborative features beyond simple email. Zimbra serves as the "system of record" for corporate decisions: emails are communication records, calendars attest to commitments, shared documents underpin operational choices. Compromising these layers means compromising the trust fabric on which organizational consensus is built.
According to the primary source, "several allow attackers not just to observe environments, but to actively rewrite them by impersonating senders without credentials." An attacker can send email as the Chief Financial Officer, retain control of the mailbox post-event, and decide whether to erase the trail or leave it visible. The Rapid7 researcher summarizes: "Send an email as your CFO without ever touching their password, and you have the front half of a very convincing BEC. Keep control of the mailbox afterward and you have the back half, too."
The consequence extends beyond financial loss. When Finance checks send logs and the CFO denies authorizing the wire transfer, both parties hold contradictory digital "proof." The attacker no longer needs to deceive a single employee; they deceive the verification infrastructure itself.
Calendar Warfare and Temporal Manipulation
The research describes specific "calendar warfare" techniques. An emergency meeting can materialize in an executive's calendar with a plausible organizer, popup reminders, and a malicious Zoom link. When the alert fires, the victim is not evaluating a suspicious email that arrived thirty seconds earlier; they are joining a meeting that has sat in their calendar for two days.
Temporal manipulation is critical. Fake meetings do not require an immediate click; they exploit persistence in the scheduling system to build retrospective legitimacy. The researcher observes that "Classic BEC abuses the trust between two people. The scenario we've discussed here abuses the machinery those people use to decide who to trust in the first place."
The document does not specify documented cases of victims who have actually suffered this technique in real-world attacks; the scenarios presented are demonstrative, based on proof-of-concept derived from the discovered vulnerabilities.
"Whether the attacker cleans up or leaves the trail, they are shaping the organization's perception of reality." — Rapid7 Researcher
Threat Context: From CVE-2024-45519 to LAUNDRY BEAR
The Rapid7 research sits within an ecosystem of active, documented exploitation. CVE-2024-45519, a command injection in the postjournal service with unauthenticated command execution, was added to CISA's Known Exploited Vulnerabilities Catalog on October 3, 2024. The mechanism exploited base64 payloads in CC fields.
CVE-2025-27915, an XSS in the Classic Web Client, was used as a zero-day against Brazilian military targets for email theft and silent forwarding, and added to the KEV in October 2025. CVE-2026-73570, command injection via SNMP, was added to the CISA KEV on August 21, 2026; Shadowserver detected over 260 compromised instances.
CISA confirms that Russian APT LAUNDRY BEAR has conducted campaigns against Zimbra users since July 2025. The group uses view-based exploits requiring only the viewing of a malicious email, with no additional interaction needed. The 'Ulej' capability exploits CVE-2025-66376, an XSS with CVSS 7.2 HIGH, to exfiltrate email, organizational directory, and 2FA tokens. The campaign operated for approximately 90 days.
No infrastructure overlap emerges linking LAUNDRY BEAR to the calendar and document manipulation techniques described by Rapid7; CISA's focus remains on traditional exfiltration.
Why Traditional Forensics Fails
The reader impact demands attention on a specific axis: traditional disaster recovery and forensics procedures become unreliable. Email send logs, document timestamps, shared versions on the platform — all elements considered objective proof — lose evidentiary value when the platform itself is compromised at the write level.
Legal, HR, and finance teams must recalibrate verification procedures. The risk is no longer just direct financial loss, but corporate decisions based on manipulated reality, with compliance, insurance, and reputational fallout. Traditional anti-phishing training becomes insufficient: the attack does not require suspicious clicks; it exploits inherent trust in internal infrastructure.
The dossier does not specify specific corrective measures released by Zimbra for the reality-manipulation vulnerabilities. It also does not document the scope of available patches nor the release timeline for the over 50 discovered vulnerabilities.
Why This Matters
The brief does not document specific operational actions by the primary source. The dossier does not specify corrective measures or recommended out-of-band verification procedures. No explicit recommendation emerges on network segmentation, platform hardening, or additional authentication protocols.
What the source makes clear is the structural limit: when the attacker controls the "system of record," independent verification must occur outside that system. The dossier does not, however, detail how to implement such separation. It is not documented whether Zimbra has released patches for the specific impersonation and calendar manipulation vulnerabilities, nor which versions remediate them.
The source does not specify the nature of exposed data beyond the described manipulation mechanisms. The sample of explicitly cited vulnerabilities (four CVEs) represents a fraction of the over 50 discovered; the exact CVEs for the remainder are not listed in the available material.
From Fraud to Psyop: The New Risk Perimeter
The Rapid7 research redefines the BEC risk perimeter. No longer credential theft and fraudulent wire transfers, but "manufactured enterprise reality" — reality built piece by piece through compromise of the collaborative platform. The researcher uses the phrase "rewriting reality" in a technical, not metaphorical, sense: the attacker rewrites the shared records on which the organization bases decisions, contracts, and minutes.
The internal consistency of manipulated scenarios makes them particularly insidious. Emails, calendars, and shared documents reinforce each other: a fake meeting in the calendar lends plausibility to a follow-up email; an altered document in the corporate repository legitimizes the constructed narrative. The victim does not recognize the anomaly because every element appears consistent with the system.
This reading remains editorial analysis based on documented mechanisms, not confirmed attack cases. No source in the dossier attributes operational use of "calendar warfare" or document tampering techniques to known threat actors.
FAQ
Which CVEs have been confirmed exploited in-the-wild?
According to the dossier: CVE-2024-45519 (CISA KEV, October 2024), CVE-2025-27915 (KEV, October 2025, Brazilian military targets), CVE-2026-73570 (KEV, August 2026, over 260 instances), CVE-2025-66376 (LAUNDRY BEAR, token and directory exfiltration).
Are the "rewriting reality" techniques already used in real attacks?
The dossier does not document confirmed cases. The described scenarios are proof-of-concept based on the discovered vulnerabilities. Documented exploitation by CISA and Google TAG concerns exfiltration and credential theft, not calendar or document manipulation.
Why is Zimbra a recurring target?
Rapid7 documented a historical exploitation pattern since 2022. Google TAG observed four separate groups exploit CVE-2023-37580 in 2023. The platform is attractive for its broad attack surface and the frequency of patches not immediately deployed.
Information verified against cited sources and current as of publication.
Sources
- https://www.rapid7.com/blog/post/ve-business-email-compromise-rewriting-reality-zimbra-cve
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a
- https://www.rapid7.com/blog/post/2022/08/17/active-exploitation-of-multiple-vulnerabilities-in-zimbra-collaboration-suite/
- https://blog.google/threat-analysis-group/zimbra-0-day-used-to-target-international-government-organizations/
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.