Critical Zimbra RCE flaw now actively exploited in attacks
… CERT Polska also asked admins to check their logs for suspicious activity, such as the Zimbra service restarting on its own, and for files created in the /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty base/webapps/, and /tmp/ folders by user zimbra over the last 30 days. …