A zero-day vulnerability in Mitel MiCollab is still present three months after being reported, according to cybersecurity researchers watchTowr.
The flaw allows threat actors to access sensitive information about user accounts, and Mitel has not yet released a patch for it.
WatchTowr has suggested several mitigations to minimize the risk, including limiting access to the MiCollab server and implementing strong firewall rules.
Users are advised to monitor logs for suspicious activity and disable or restrict access to the ReconcileWIzard servlet, if possible.