Story perspectives
CISA Warns of Exploited Zimbra Vulnerability Amid Fortinet Attacks
1/24/2026
1 of 1
Story summary
- The Cybersecurity and Infrastructure Security Agency (CISA) urges federal agencies to patch the Zimbra Collaboration Suite to fix CVE-2025-68645, a critical local file inclusion vulnerability actively exploited in targeted attacks.
- Patches for Zimbra were released in November 2025.
- Fortinet confirmed recent attacks bypass FortiCloud SSO authentication, affecting fully patched devices.
- Fortinet advises restricting administrative access and disabling the FortiCloud SSO feature as a temporary measure.
