FAIL › dossier
Synacor
VENDOR· dossier confidence 20%
Synacor’s Zimbra platform is plagued by a relentless stream of critical and high-severity vulnerabilities, many of which remain unpatched long enough to be actively exploited by threat actors. The company’s track record shows a systemic inability to secure core components like the Calendar, Classic UI, and mailbox import functions against RCE, XSS, and SSRF attacks.
PROFILE
Categoryemail-collaboration-softwareWhat they doSynacor develops and maintains Zimbra Collaboration Suite, an open-source email and collaboration platform deployed across enterprise and government environments.
Websitehttps://www.synacor.com ↗
SECURITY POSTURE
Synacor exhibits a chronic vulnerability management failure, with critical RCEs, XSS, and SSRF flaws persisting across multiple years and actively exploited in ransomware campaigns.
Notable failures
- CVE-2022-37042: chained RCE via MailboxImportServlet
- CVE-2025-66376: actively exploited XSS linked to ransomware
- CVE-2025-68645: PHP RFI enabling remote code execution
Patterns: repeated unpatched RCE and XSS in core ZCS components; insufficient input sanitization across Calendar, Classic UI, and ProxyServlet; active exploitation of legacy XSS vectors in Classic Web Client
FAILURE HISTORY · 20
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2026-01-22 | CVE-2025-68645 | high | Synacor's Zimbra Collaboration Suite (ZCS) had an unpatched PHP RFI vulnerability actively exploited for remote code execution |
| 2025-07-07 | CVE-2019-9621 | high | Synacor's Zimbra Collaboration Suite suffered an SSRF vulnerability actively exploited by ransomware |
| 2026-08-21 | CVE-2026-73570 | high | An unauthenticated attacker can execute arbitrary OS commands via crafted SMTP requests in Zimbra Collaboration Suite due to an OS command injection flaw. |
| 2024-10-03 | CVE-2024-45519 | high | Synacor ZCS unauthenticated RCE in postjournal service actively exploited by threat actors. |
| 2022-08-11 | CVE-2022-37042 | critical | Synacor's Zimbra Collaboration Suite suffered an authentication bypass vulnerability chained with an unpatched RCE flaw, enabling ransomware actors to execute arbitrary code without authentication. |
| 2022-08-11 | CVE-2022-27925 | critical | An unpatched arbitrary file upload flaw in Zimbra's mboximport functionality allowed authenticated attackers to execute remote code, which was chained with an unauthenticated RCE to compromise systems. |
| 2022-08-04 | CVE-2022-27924 | critical | Unpatched command injection flaw in Synacor Zimbra allowed memcache command injection leading to arbitrary cache overwrites and active ransomware exploitation. |
| 2022-01-10 | CVE-2019-9670 | high | Synacor's Zimbra Collaboration Suite suffered an unpatched XXE vulnerability actively exploited in the wild, exposing organizations to data theft and ransomware. |
| 2026-02-17 | CVE-2020-7796 | high | Synacor's Zimbra Collaboration Suite left vulnerable to SSRF, exploited in the wild |
| 2025-10-07 | CVE-2025-27915 | high | Synacor Zimbra CSVuln |
| 2025-05-19 | CVE-2024-27443 | high | Synacor's Zimbra Collaboration Suite (ZCS) had an unpatched XSS vulnerability actively exploited by ransomware |
| 2023-07-27 | CVE-2023-37580 | high | Zimbra Collaboration Suite has an actively exploited XSS vulnerability impacting data integrity and confidentiality. |
| 2023-04-03 | CVE-2022-27926 | high | Synacor's Zimbra Collaboration Suite (ZCS) had an unpatched XSS vulnerability actively exploited in the wild |
| 2022-10-20 | CVE-2022-41352 | high | Synacor's Zimbra Collaboration Suite (ZCS) had an unpatched RCE flaw allowing attackers to upload arbitrary files and gain access to any user account. |
| 2022-04-19 | CVE-2018-6882 | critical | Synacor's Zimbra Collaboration Suite has a critical XSS vulnerability actively exploited by ransomware groups, demonstrating a failure to patch critical flaws promptly. |
| 2022-02-25 | CVE-2022-24682 | critical | Zimbra Collaborate Suite has a critical XSS vulnerability actively exploited by ransomware actors, demonstrating poor vulnerability management by Synacor. |
| 2026-03-18 | CVE-2025-66376 | high | Synacor ZCS Classic UI XSS via CSS @import in email HTML is actively exploited and linked to ransomware campaigns. |
| 2025-02-25 | CVE-2023-34192 | high | Zimbra Collaboration Suite has an actively exploited XSS vulnerability allowing code execution via the autoSaveDraft function. |
| 2026-04-20 | CVE-2025-48700 | high | Synacor ZCS XSS vulnerability (CVE-2025-48700) allows arbitrary JavaScript execution in user sessions, enabling unauthorized access to sensitive data. |
| 2022-08-12 | CVE-2022-37042 | critical | CVE-2022-37042: Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality tha |
DOSSIER SOURCES
- Company Database Search · www.edgarcompany.sec.gov
- Vulnérabilité dans Synacor Zimbra Collaboration (18 juin 2026) · www.globalsecuritymag.fr
- How to pronounce Synacor | HowToPronounce.com · www.howtopronounce.com
- Company Database Search · www.edgarcompany.sec.gov
- Time.is - exact time, any time zone · time.is
- How to pronounce Synacor | HowToPronounce.com · www.howtopronounce.com
Open questions: Exact founding year and headquarters location not explicitly confirmed in provided evidence · Current ownership structure and employee count not explicitly confirmed in provided evidence
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-16 04:53:18.716681+00:00