EXPOSURES › CVE-2025-68645
CVE-2025-68645
HIGH ⌖ ON CISA KEV · EXPLOITEDSynacor's Zimbra Collaboration Suite (ZCS) had an unpatched PHP RFI vulnerability actively exploited for remote code execution
Synacor's Zimbra Collaboration Suite had a critical PHP remote file inclusion vulnerability that was actively exploited, allowing attackers to execute arbitrary code. This persistence of unpatched vulnerabilities in core components like mailbox import and Classic UI is a systemic failure in Synacor's vulnerability management process, leading to its products being targeted by ransomware campaigns.
Shame score — Chronic vulnerability management failure leading to actively exploited unpatched RCEs in core components
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Synacor Zimbra Collaboration Suite (ZCS) contains a PHP remote file inclusion vulnerability that could allow for remote attackers to craft requests to the /h/rest endpoint to influence internal request dispatching, allowing inclusion of arbitrary files from the WebRoot directory.