Zimbra Collaboration

Synacor

Actively exploited vulnerabilities

The US cybersecurity agency CISA lists these vulnerabilities in its catalog of Known Exploited Vulnerabilities. Check your version and patch or mitigate promptly.

  • CVE-2022-37042Synacor Zimbra Collaboration Suite (ZCS) Authentication Bypass VulnerabilityRansomware

    9.8 critical · over the network, without login · CISA deadline was 1 Sept 22

  • CVE-2022-27924Synacor Zimbra Collaboration Suite (ZCS) Command Injection VulnerabilityRansomware

    7.5 high · over the network, without login · CISA deadline was 25 Aug 22

  • CVE-2022-27925Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload VulnerabilityRansomware

    7.2 high · over the network, with admin rights only · CISA deadline was 1 Sept 22

  • CVE-2022-24682Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting VulnerabilityRansomware

    6.1 medium · over the network, without login, needs user action · CISA deadline was 11 Mar 22

  • CVE-2018-6882Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) VulnerabilityRansomware

    6.1 medium · over the network, without login, needs user action · CISA deadline was 10 May 22

  • CVE-2019-9670Synacor Zimbra Collaboration Suite (ZCS) Improper Restriction of XML External Entity Reference

    9.8 critical · over the network, without login · CISA deadline was 10 Jul 22

  • CVE-2022-41352Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability

    9.8 critical · over the network, without login · CISA deadline was 10 Nov 22

  • CVE-2024-45519Synacor Zimbra Collaboration Suite (ZCS) Command Execution Vulnerability

    9.8 critical · over the network, without login · CISA deadline was 24 Oct 24

  • CVE-2020-7796Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability

    9.8 critical · over the network, without login · CISA deadline was 10 Mar

  • CVE-2023-34192Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability

    9.0 critical · over the network, with a basic account, needs user action · CISA deadline was 18 Mar 25

  • CVE-2026-73570Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability

    8.9 high · over the network, without login · CISA deadline was 24 Aug

  • CVE-2025-68645Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability

    8.8 high · over the network, without login, needs user action · CISA deadline was 12 Feb

  • CVE-2019-9621Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) Vulnerability

    7.5 high · over the network, without login · CISA deadline was 28 Jul 25

  • CVE-2022-27926Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability

    6.1 medium · over the network, without login, needs user action · CISA deadline was 24 Apr 23

  • CVE-2023-37580Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability

    6.1 medium · over the network, without login, needs user action · CISA deadline was 17 Aug 23

  • CVE-2024-27443Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability

    6.1 medium · over the network, without login, needs user action · CISA deadline was 9 Jun 25

  • CVE-2025-66376Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability

    6.1 medium · over the network, without login, needs user action · CISA deadline was 1 Apr

  • CVE-2025-48700Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability

    6.1 medium · over the network, without login, needs user action · CISA deadline was 23 Apr

  • CVE-2025-27915Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability

    5.4 medium · over the network, with a basic account, needs user action · CISA deadline was 28 Oct 25

Source: CISA KEV. The CVE is matched to the product automatically — when in doubt, the linked NVD entry applies.

BSI security advisories

Advisories the German BSI (CERT-Bund) published for this product. Whether your version is affected is stated in the advisory itself.

All BSI advisories →

Version history & changelog · as detected by patchletter

No releases recorded yet — the source was just added.

Never miss a Zimbra Collaboration update

We check the source daily and email you — instantly or as a digest. Free, one-click unsubscribe.

Watch Zimbra Collaboration

Embed this badge

Shows the current Zimbra Collaboration version and updates itself. Free to use, no account needed.

Zimbra Collaboration badge
[![Zimbra Collaboration](https://patchletter.com/badge/zimbra.svg)](https://patchletter.com/en/software/zimbra)
https://patchletter.com/badge/zimbra.svg

Also available: ?v=eol (end of support) and ?v=cve (actively exploited).

Related tools in Collaboration & Communication