EXPOSURES › CVE-2018-6882
CVE-2018-6882
CRITICAL ⌖ ON CISA KEV · EXPLOITEDSynacor's Zimbra Collaboration Suite has a critical XSS vulnerability actively exploited by ransomware groups, demonstrating a failure to patch critical flaws promptly.
A cross-site scripting vulnerability in Synacor Zimbra Collaboration Suite allows attackers to inject arbitrary web scripts, potentially leading to data theft or system compromise. DIB organizations using Zimbra face increased risk of ransomware infection and compliance violations (NIST 800-171 controls 3.1.1, 3.1.2, 3.1.3) and should immediately patch and review security configurations.
Shame score — The persistent, unpatched nature of the vulnerability and its exploitation by ransomware highlights a significant and avoidable security management failure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that might allow remote attackers to inject arbitrary web script or HTML.