FAIL › dossier
Zimbra Collaboration Suite (ZCS)
PRODUCT· dossier confidence 20%
Zimbra Collaboration Suite suffers from a relentless stream of critical and high-severity vulnerabilities, many remaining unpatched long enough to be actively exploited by ransomware campaigns. The platform's core components like mailbox import, Classic UI, and postjournal services are repeatedly targeted for RCE, XSS, and SSRF attacks.
PROFILE
Categorycollaboration_softwareWhat they doZimbra Collaboration Suite (ZCS) is an open-source email and collaboration platform providing mail, calendar, and document management.
Websitehttps://www.zimbra.com ↗
SECURITY POSTURE
Chronic vulnerability management failure with critical RCEs, XSS, and SSRF flaws remaining unpatched long enough for active exploitation by ransomware and threat actors.
Notable failures
- CVE-2022-37042 critical RCE via MailboxImportServlet
- CVE-2022-27925 critical RCE0day in mboximport
- CVE-2025-66376 high XSS actively exploited in ransomware campaigns
- CVE-2024-45519 high RCE in postjournal service
- CVE-2025-68645 high RCE via PHP remote file inclusion
- CVE-2022-41352 high arbitrary file upload via cpio
Patterns: repeated unpatched RCE and XSS in core components; insufficient input sanitization in Classic UI and Calendar features; critical flaws chained together for remote code execution
FAILURE HISTORY · 17
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2026-01-22 | CVE-2025-68645 | high | Synacor's Zimbra Collaboration Suite (ZCS) had an unpatched PHP RFI vulnerability actively exploited for remote code execution |
| 2025-07-07 | CVE-2019-9621 | high | Synacor's Zimbra Collaboration Suite suffered an SSRF vulnerability actively exploited by ransomware |
| 2026-08-21 | CVE-2026-73570 | high | An unauthenticated attacker can execute arbitrary OS commands via crafted SMTP requests in Zimbra Collaboration Suite due to an OS command injection flaw. |
| 2024-10-03 | CVE-2024-45519 | high | Synacor ZCS unauthenticated RCE in postjournal service actively exploited by threat actors. |
| 2022-08-11 | CVE-2022-37042 | critical | Synacor's Zimbra Collaboration Suite suffered an authentication bypass vulnerability chained with an unpatched RCE flaw, enabling ransomware actors to execute arbitrary code without authentication. |
| 2022-08-11 | CVE-2022-27925 | critical | An unpatched arbitrary file upload flaw in Zimbra's mboximport functionality allowed authenticated attackers to execute remote code, which was chained with an unauthenticated RCE to compromise systems. |
| 2022-08-04 | CVE-2022-27924 | critical | Unpatched command injection flaw in Synacor Zimbra allowed memcache command injection leading to arbitrary cache overwrites and active ransomware exploitation. |
| 2022-01-10 | CVE-2019-9670 | high | Synacor's Zimbra Collaboration Suite suffered an unpatched XXE vulnerability actively exploited in the wild, exposing organizations to data theft and ransomware. |
| 2025-10-07 | CVE-2025-27915 | high | Synacor Zimbra CSVuln |
| 2025-05-19 | CVE-2024-27443 | high | Synacor's Zimbra Collaboration Suite (ZCS) had an unpatched XSS vulnerability actively exploited by ransomware |
| 2023-07-27 | CVE-2023-37580 | high | Zimbra Collaboration Suite has an actively exploited XSS vulnerability impacting data integrity and confidentiality. |
| 2023-04-03 | CVE-2022-27926 | high | Synacor's Zimbra Collaboration Suite (ZCS) had an unpatched XSS vulnerability actively exploited in the wild |
| 2022-10-20 | CVE-2022-41352 | high | Synacor's Zimbra Collaboration Suite (ZCS) had an unpatched RCE flaw allowing attackers to upload arbitrary files and gain access to any user account. |
| 2022-04-19 | CVE-2018-6882 | critical | Synacor's Zimbra Collaboration Suite has a critical XSS vulnerability actively exploited by ransomware groups, demonstrating a failure to patch critical flaws promptly. |
| 2026-03-18 | CVE-2025-66376 | high | Synacor ZCS Classic UI XSS via CSS @import in email HTML is actively exploited and linked to ransomware campaigns. |
| 2025-02-25 | CVE-2023-34192 | high | Zimbra Collaboration Suite has an actively exploited XSS vulnerability allowing code execution via the autoSaveDraft function. |
| 2026-04-20 | CVE-2025-48700 | high | Synacor ZCS XSS vulnerability (CVE-2025-48700) allows arbitrary JavaScript execution in user sessions, enabling unauthorized access to sensitive data. |
DOSSIER SOURCES
- Zimbra Forums - Index page · forums.zimbra.org
- CCSI - Consensus Cloud Solutions, Inc. Company Profile · stockinvest.us
- Zoominfo Technologies Inc, ZOM:FRA profile - FT.com · markets.ft.com
Open questions: Current patch cycle SLA for ZCS · Number of active ZCS deployments in DIB environments
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-17 04:17:19.559530+00:00