Drooid Logo
Back to today’s briefing

Story perspectives

CISA Warns of Exploited Zimbra Vulnerability Amid Fortinet Attacks

1/24/2026

28 5 Full Breakdown

1 of 1

Story summary
  • The Cybersecurity and Infrastructure Security Agency (CISA) urges federal agencies to patch the Zimbra Collaboration Suite to fix CVE-2025-68645, a critical local file inclusion vulnerability actively exploited in targeted attacks.
  • Patches for Zimbra were released in November 2025.
  • Fortinet confirmed recent attacks bypass FortiCloud SSO authentication, affecting fully patched devices.
  • Fortinet advises restricting administrative access and disabling the FortiCloud SSO feature as a temporary measure.