Zimbra Collaboration
Synacor
Actively exploited vulnerabilities
The US cybersecurity agency CISA lists these vulnerabilities in its catalog of Known Exploited Vulnerabilities. Check your version and patch or mitigate promptly.
- CVE-2022-37042Synacor Zimbra Collaboration Suite (ZCS) Authentication Bypass VulnerabilityRansomware
9.8 critical · over the network, without login · CISA deadline was 1 Sept 22
7.5 high · over the network, without login · CISA deadline was 25 Aug 22
- CVE-2022-27925Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload VulnerabilityRansomware
7.2 high · over the network, with admin rights only · CISA deadline was 1 Sept 22
6.1 medium · over the network, without login, needs user action · CISA deadline was 11 Mar 22
- CVE-2018-6882Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) VulnerabilityRansomware
6.1 medium · over the network, without login, needs user action · CISA deadline was 10 May 22
- CVE-2019-9670Synacor Zimbra Collaboration Suite (ZCS) Improper Restriction of XML External Entity Reference
9.8 critical · over the network, without login · CISA deadline was 10 Jul 22
- CVE-2022-41352Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability
9.8 critical · over the network, without login · CISA deadline was 10 Nov 22
- CVE-2024-45519Synacor Zimbra Collaboration Suite (ZCS) Command Execution Vulnerability
9.8 critical · over the network, without login · CISA deadline was 24 Oct 24
- CVE-2020-7796Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability
9.8 critical · over the network, without login · CISA deadline was 10 Mar
- CVE-2023-34192Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
9.0 critical · over the network, with a basic account, needs user action · CISA deadline was 18 Mar 25
- CVE-2026-73570Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
8.9 high · over the network, without login · CISA deadline was 24 Aug
- CVE-2025-68645Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability
8.8 high · over the network, without login, needs user action · CISA deadline was 12 Feb
- CVE-2019-9621Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) Vulnerability
7.5 high · over the network, without login · CISA deadline was 28 Jul 25
- CVE-2022-27926Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
6.1 medium · over the network, without login, needs user action · CISA deadline was 24 Apr 23
- CVE-2023-37580Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
6.1 medium · over the network, without login, needs user action · CISA deadline was 17 Aug 23
- CVE-2024-27443Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
6.1 medium · over the network, without login, needs user action · CISA deadline was 9 Jun 25
- CVE-2025-66376Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability
6.1 medium · over the network, without login, needs user action · CISA deadline was 1 Apr
- CVE-2025-48700Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability
6.1 medium · over the network, without login, needs user action · CISA deadline was 23 Apr
- CVE-2025-27915Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability
5.4 medium · over the network, with a basic account, needs user action · CISA deadline was 28 Oct 25
Source: CISA KEV. The CVE is matched to the product automatically — when in doubt, the linked NVD entry applies.
BSI security advisories
Advisories the German BSI (CERT-Bund) published for this product. Whether your version is affected is stated in the advisory itself.
- Synacor Zimbra: Mehrere Schwachstellen
WID-SEC-W-2026-2429 · 20 Aug
- Synacor Zimbra: Mehrere Schwachstellen
WID-SEC-W-2026-1735 · 14 Aug
- Synacor Zimbra Classic Web Client: Schwachstelle ermöglicht Cross-Site Scripting
WID-SEC-W-2026-2216 · 7 Jul
- Synacor Zimbra: Schwachstelle ermöglicht nicht spezifizierten Angriff
WID-SEC-W-2026-1909 · 12 Jun
Version history & changelog · as detected by patchletter
No releases recorded yet — the source was just added.
Never miss a Zimbra Collaboration update
We check the source daily and email you — instantly or as a digest. Free, one-click unsubscribe.
Watch Zimbra CollaborationEmbed this badge
Shows the current Zimbra Collaboration version and updates itself. Free to use, no account needed.
[](https://patchletter.com/en/software/zimbra)https://patchletter.com/badge/zimbra.svgAlso available: ?v=eol (end of support) and ?v=cve (actively exploited).