Zimbra Vulnerabilities
Synacor owns Zimbra, the email and collaboration suite (Zimbra Collaboration) that every Synacor entry in KEV refers to. The database tracks 19 Zimbra CVE records. CISA lists 19 of them as exploited in the wild, most recently on 2026-08-21. The most affected products are Zimbra Collaboration Suite (ZCS), Zimbra Collaboration Suite (ZCS), Zimbra Collaborate Suite (ZCS).
Recently Exploited Zimbra CVEs
Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability
Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability
Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability
Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability
Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability
Affected Products
4 products| Product | CVEs | KEV | Latest |
|---|---|---|---|
| Zimbra Collaboration Suite (ZCS) | 16 | 16 | 2026-08-21 |
| Zimbra Collaboration Suite (ZCS) | 1 | 1 | 2026-01-22 |
| Zimbra Collaborate Suite (ZCS) | 1 | 1 | 2022-02-25 |
| Zimbra Collaboration Suite | 1 | 1 | 2026-02-17 |
Security Advisories
Weakness Types
All Zimbra CVEs
19 records| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2026-73570 | Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability | Zimbra | 8.9 | 71.7% | KEV | 2026-08-13 |
| CVE-2025-48700 | Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability | - | 6.1 | 1.7% | KEV | 2025-06-23 |
| CVE-2025-66376 | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability | Zimbra | 7.2 | 20.2% | KEV | 2026-01-05 |
| CVE-2020-7796 | Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability | - | 9.8 | 84.4% | KEV | 2020-02-18 |
| CVE-2025-68645 | Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability | - | 8.8 | 48.9% | KEV | 2025-12-22 |
| CVE-2025-27915 | Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability | - | 5.4 | 4.1% | KEV | 2025-03-12 |
| CVE-2019-9621 | Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) Vulnerability | - | 7.5 | 81.0% | KEV | 2019-04-30 |
| CVE-2024-27443 | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability | - | 6.1 | 23.6% | KEV | 2024-08-12 |
| CVE-2023-34192 | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability | - | 9.0 | 77.3% | KEV | 2023-07-06 |
| CVE-2024-45519 | Synacor Zimbra Collaboration Suite (ZCS) Command Execution Vulnerability | - | 10.0 | 99.9% | KEV | 2024-10-02 |
| CVE-2023-37580 | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability | - | 6.1 | 49.1% | KEV | 2023-07-31 |
| CVE-2022-27926 | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability | - | 6.1 | 17.6% | KEV | 2022-04-20 |
| CVE-2022-41352 | Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability | - | 9.8 | 95.5% | KEV | 2022-09-26 |
| CVE-2022-27925 | Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability | - | 7.2 | 98.7% | KEV | 2022-04-20 |
| CVE-2022-37042 | Synacor Zimbra Collaboration Suite (ZCS) Authentication Bypass Vulnerability | - | 9.8 | 91.9% | KEV | 2022-08-11 |
| CVE-2022-27924 | Synacor Zimbra Collaboration Suite (ZCS) Command Injection Vulnerability | - | 9.8 | 93.9% | KEV | 2022-04-20 |
| CVE-2018-6882 | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability | - | 6.1 | 29.8% | KEV | 2018-03-27 |
| CVE-2022-24682 | Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability | - | 6.1 | 30.9% | KEV | 2022-02-09 |
| CVE-2019-9670 | Synacor Zimbra Collaboration Suite (ZCS) Improper Restriction of XML External Entity Reference | - | 9.8 | 100.0% | KEV | 2019-05-29 |
Frequently Asked Questions
How many Zimbra vulnerabilities are actively exploited?→
19 Zimbra CVEs are in the CISA Known Exploited Vulnerabilities catalog as of 2026-10-09. The latest was added on 2026-08-21.
Which Zimbra vulnerabilities are used in ransomware attacks?→
CISA marks 6 Zimbra KEV entries as known to be used in ransomware campaigns, including CVE-2022-41352, CVE-2022-27925, CVE-2022-37042, CVE-2022-27924, CVE-2018-6882.
Which Zimbra products have the most exploited vulnerabilities?→
- +Zimbra Collaboration Suite (ZCS): 16 CVEs (16 in KEV)
- + Zimbra Collaboration Suite (ZCS): 1 CVE (1 in KEV)
- +Zimbra Collaborate Suite (ZCS): 1 CVE (1 in KEV)
- +Zimbra Collaboration Suite: 1 CVE (1 in KEV)
Where does Zimbra publish security advisories?→
Zimbra publishes security advisories at https://wiki.zimbra.com/wiki/Security_Center. Check the vendor advisory for fixed versions and workarounds before applying updates.
CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Vendor and product names for exploited CVEs follow the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not affiliated with or endorsed by Zimbra, MITRE, CISA, or FIRST.