Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance. These memcache commands becomes unescaped, causing an overwrite of arbitrary cached entries.
https://www.greynoise.io/blog/unmasking-cisas-hidden-kev-ransomware-updates
https://securityaffairs.com/169708/apt/apt29-target-zimbra-and-jetbrains-teamcity.html
https://thehackernews.com/2024/10/cisa-warns-of-threat-actors-exploiting.html
https://www.ic3.gov/Media/News/2024/241010.pdf
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-215a
https://www.tenable.com/cyber-exposure/tenable-2022-threat-landscape-report
https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-228a
https://github.com/alsyundawy/eradicate-zimbra-malware
https://github.com/Josexv1/CVE-2022-27925
https://github.com/tr3ss/gofetch
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-27924
https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories