Skip to content
COOEY

FAIL › dossier

Synacor

VENDOR

· dossier confidence 20%

Synacor’s Zimbra platform is plagued by a relentless stream of critical and high-severity vulnerabilities, many of which remain unpatched long enough to be actively exploited by threat actors. The company’s track record shows a systemic inability to secure core components like the Calendar, Classic UI, and mailbox import functions against RCE, XSS, and SSRF attacks.

PROFILE
Categoryemail-collaboration-softwareWhat they doSynacor develops and maintains Zimbra Collaboration Suite, an open-source email and collaboration platform deployed across enterprise and government environments. Websitehttps://www.synacor.com ↗
SECURITY POSTURE

Synacor exhibits a chronic vulnerability management failure, with critical RCEs, XSS, and SSRF flaws persisting across multiple years and actively exploited in ransomware campaigns.

Notable failures
  • CVE-2022-37042: chained RCE via MailboxImportServlet
  • CVE-2025-66376: actively exploited XSS linked to ransomware
  • CVE-2025-68645: PHP RFI enabling remote code execution
Patterns: repeated unpatched RCE and XSS in core ZCS components; insufficient input sanitization across Calendar, Classic UI, and ProxyServlet; active exploitation of legacy XSS vectors in Classic Web Client
FAILURE HISTORY · 20
DATEEVENTSEVSUMMARY
2026-01-22 CVE-2025-68645 high Synacor's Zimbra Collaboration Suite (ZCS) had an unpatched PHP RFI vulnerability actively exploited for remote code execution
2025-07-07 CVE-2019-9621 high Synacor's Zimbra Collaboration Suite suffered an SSRF vulnerability actively exploited by ransomware
2026-08-21 CVE-2026-73570 high An unauthenticated attacker can execute arbitrary OS commands via crafted SMTP requests in Zimbra Collaboration Suite due to an OS command injection flaw.
2024-10-03 CVE-2024-45519 high Synacor ZCS unauthenticated RCE in postjournal service actively exploited by threat actors.
2022-08-11 CVE-2022-37042 critical Synacor's Zimbra Collaboration Suite suffered an authentication bypass vulnerability chained with an unpatched RCE flaw, enabling ransomware actors to execute arbitrary code without authentication.
2022-08-11 CVE-2022-27925 critical An unpatched arbitrary file upload flaw in Zimbra's mboximport functionality allowed authenticated attackers to execute remote code, which was chained with an unauthenticated RCE to compromise systems.
2022-08-04 CVE-2022-27924 critical Unpatched command injection flaw in Synacor Zimbra allowed memcache command injection leading to arbitrary cache overwrites and active ransomware exploitation.
2022-01-10 CVE-2019-9670 high Synacor's Zimbra Collaboration Suite suffered an unpatched XXE vulnerability actively exploited in the wild, exposing organizations to data theft and ransomware.
2026-02-17 CVE-2020-7796 high Synacor's Zimbra Collaboration Suite left vulnerable to SSRF, exploited in the wild
2025-10-07 CVE-2025-27915 high Synacor Zimbra CSVuln
2025-05-19 CVE-2024-27443 high Synacor's Zimbra Collaboration Suite (ZCS) had an unpatched XSS vulnerability actively exploited by ransomware
2023-07-27 CVE-2023-37580 high Zimbra Collaboration Suite has an actively exploited XSS vulnerability impacting data integrity and confidentiality.
2023-04-03 CVE-2022-27926 high Synacor's Zimbra Collaboration Suite (ZCS) had an unpatched XSS vulnerability actively exploited in the wild
2022-10-20 CVE-2022-41352 high Synacor's Zimbra Collaboration Suite (ZCS) had an unpatched RCE flaw allowing attackers to upload arbitrary files and gain access to any user account.
2022-04-19 CVE-2018-6882 critical Synacor's Zimbra Collaboration Suite has a critical XSS vulnerability actively exploited by ransomware groups, demonstrating a failure to patch critical flaws promptly.
2022-02-25 CVE-2022-24682 critical Zimbra Collaborate Suite has a critical XSS vulnerability actively exploited by ransomware actors, demonstrating poor vulnerability management by Synacor.
2026-03-18 CVE-2025-66376 high Synacor ZCS Classic UI XSS via CSS @import in email HTML is actively exploited and linked to ransomware campaigns.
2025-02-25 CVE-2023-34192 high Zimbra Collaboration Suite has an actively exploited XSS vulnerability allowing code execution via the autoSaveDraft function.
2026-04-20 CVE-2025-48700 high Synacor ZCS XSS vulnerability (CVE-2025-48700) allows arbitrary JavaScript execution in user sessions, enabling unauthorized access to sensitive data.
2022-08-12 CVE-2022-37042 critical CVE-2022-37042: Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality tha
DOSSIER SOURCES
Open questions: Exact founding year and headquarters location not explicitly confirmed in provided evidence · Current ownership structure and employee count not explicitly confirmed in provided evidence
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-16 04:53:18.716681+00:00