Zimbra Collaboration

Synacor

Are you Synacor? Claim this page

Actively exploited vulnerabilities

The US cybersecurity agency CISA lists these vulnerabilities in its catalog of Known Exploited Vulnerabilities. What CISA does not carry does not appear in this list — even where it is being exploited.

  • CVE-2022-37042Synacor Zimbra Collaboration Suite (ZCS) Authentication Bypass VulnerabilityRansomware

    9.8 critical · over the network, without login · CISA deadline was 1 Sept 22

  • CVE-2022-41352Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload VulnerabilityRansomware

    9.8 critical · over the network, without login · CISA deadline was 10 Nov 22

  • CVE-2022-27924Synacor Zimbra Collaboration Suite (ZCS) Command Injection VulnerabilityRansomware

    7.5 high · over the network, without login · CISA deadline was 25 Aug 22

  • CVE-2022-27925Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload VulnerabilityRansomware

    7.2 high · over the network, with admin rights only · CISA deadline was 1 Sept 22

  • CVE-2022-24682Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting VulnerabilityRansomware

    6.1 medium · over the network, without login, needs user action · CISA deadline was 11 Mar 22

  • CVE-2018-6882Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) VulnerabilityRansomware

    6.1 medium · over the network, without login, needs user action · CISA deadline was 10 May 22

  • CVE-2019-9670Synacor Zimbra Collaboration Suite (ZCS) Improper Restriction of XML External Entity Reference

    9.8 critical · over the network, without login · CISA deadline was 10 Jul 22

  • CVE-2024-45519Synacor Zimbra Collaboration Suite (ZCS) Command Execution Vulnerability

    9.8 critical · over the network, without login · CISA deadline was 24 Oct 24

  • CVE-2020-7796Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability

    9.8 critical · over the network, without login · CISA deadline was 10 Mar

  • CVE-2023-34192Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability

    9.0 critical · over the network, with a basic account, needs user action · CISA deadline was 18 Mar 25

  • CVE-2026-73570Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability

    8.9 high · over the network, without login · CISA deadline was 24 Aug

  • CVE-2025-68645Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability

    8.8 high · over the network, without login, needs user action · CISA deadline was 12 Feb

  • CVE-2019-9621Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) Vulnerability

    7.5 high · over the network, without login · CISA deadline was 28 Jul 25

  • CVE-2022-27926Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability

    6.1 medium · over the network, without login, needs user action · CISA deadline was 24 Apr 23

  • CVE-2023-37580Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability

    6.1 medium · over the network, without login, needs user action · CISA deadline was 17 Aug 23

  • CVE-2024-27443Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability

    6.1 medium · over the network, without login, needs user action · CISA deadline was 9 Jun 25

  • CVE-2025-66376Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability

    6.1 medium · over the network, without login, needs user action · CISA deadline was 1 Apr

  • CVE-2025-48700Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability

    6.1 medium · over the network, without login, needs user action · CISA deadline was 23 Apr

  • CVE-2025-27915Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability

    5.4 medium · over the network, with a basic account, needs user action · CISA deadline was 28 Oct 25

Source: CISA KEV. The CVE is matched to the product automatically — when in doubt, the linked NVD entry applies.

BSI security advisories

Advisories the German BSI (CERT-Bund) published for this product. Whether your version is affected is stated in the advisory itself.

All BSI advisories →

Version history & changelog · as detected by patchletter

No releases recorded yet — the source was just added.

An email as soon as a new Zimbra Collaboration version ships

We reconcile the vendor source daily. When a new version appears, it lands in your inbox right away or bundled as a digest. The update email is free and ends with one click. Alerts about vulnerabilities and end of support are part of patchletter Pro.

Embed this badge

The badge shows the current Zimbra Collaboration version and keeps it up to date. Anyone may embed it, no account needed.

Zimbra Collaboration badge
[![Zimbra Collaboration](https://patchletter.com/badge/zimbra.svg)](https://patchletter.com/en/software/zimbra)
https://patchletter.com/badge/zimbra.svg

Also available: ?v=eol (end of support) and ?v=cve (actively exploited).

Related tools in Collaboration & Communication