Skip to content
COOEY

FAIL › dossier

Zimbra Collaboration Suite (ZCS)

PRODUCT

· dossier confidence 20%

Zimbra Collaboration Suite suffers from a relentless stream of critical and high-severity vulnerabilities, many remaining unpatched long enough to be actively exploited by ransomware campaigns. The platform's core components like mailbox import, Classic UI, and postjournal services are repeatedly targeted for RCE, XSS, and SSRF attacks.

PROFILE
Categorycollaboration_softwareWhat they doZimbra Collaboration Suite (ZCS) is an open-source email and collaboration platform providing mail, calendar, and document management. Websitehttps://www.zimbra.com ↗
SECURITY POSTURE

Chronic vulnerability management failure with critical RCEs, XSS, and SSRF flaws remaining unpatched long enough for active exploitation by ransomware and threat actors.

Notable failures
  • CVE-2022-37042 critical RCE via MailboxImportServlet
  • CVE-2022-27925 critical RCE0day in mboximport
  • CVE-2025-66376 high XSS actively exploited in ransomware campaigns
  • CVE-2024-45519 high RCE in postjournal service
  • CVE-2025-68645 high RCE via PHP remote file inclusion
  • CVE-2022-41352 high arbitrary file upload via cpio
Patterns: repeated unpatched RCE and XSS in core components; insufficient input sanitization in Classic UI and Calendar features; critical flaws chained together for remote code execution
FAILURE HISTORY · 17
DATEEVENTSEVSUMMARY
2026-01-22 CVE-2025-68645 high Synacor's Zimbra Collaboration Suite (ZCS) had an unpatched PHP RFI vulnerability actively exploited for remote code execution
2025-07-07 CVE-2019-9621 high Synacor's Zimbra Collaboration Suite suffered an SSRF vulnerability actively exploited by ransomware
2026-08-21 CVE-2026-73570 high An unauthenticated attacker can execute arbitrary OS commands via crafted SMTP requests in Zimbra Collaboration Suite due to an OS command injection flaw.
2024-10-03 CVE-2024-45519 high Synacor ZCS unauthenticated RCE in postjournal service actively exploited by threat actors.
2022-08-11 CVE-2022-37042 critical Synacor's Zimbra Collaboration Suite suffered an authentication bypass vulnerability chained with an unpatched RCE flaw, enabling ransomware actors to execute arbitrary code without authentication.
2022-08-11 CVE-2022-27925 critical An unpatched arbitrary file upload flaw in Zimbra's mboximport functionality allowed authenticated attackers to execute remote code, which was chained with an unauthenticated RCE to compromise systems.
2022-08-04 CVE-2022-27924 critical Unpatched command injection flaw in Synacor Zimbra allowed memcache command injection leading to arbitrary cache overwrites and active ransomware exploitation.
2022-01-10 CVE-2019-9670 high Synacor's Zimbra Collaboration Suite suffered an unpatched XXE vulnerability actively exploited in the wild, exposing organizations to data theft and ransomware.
2025-10-07 CVE-2025-27915 high Synacor Zimbra CSVuln
2025-05-19 CVE-2024-27443 high Synacor's Zimbra Collaboration Suite (ZCS) had an unpatched XSS vulnerability actively exploited by ransomware
2023-07-27 CVE-2023-37580 high Zimbra Collaboration Suite has an actively exploited XSS vulnerability impacting data integrity and confidentiality.
2023-04-03 CVE-2022-27926 high Synacor's Zimbra Collaboration Suite (ZCS) had an unpatched XSS vulnerability actively exploited in the wild
2022-10-20 CVE-2022-41352 high Synacor's Zimbra Collaboration Suite (ZCS) had an unpatched RCE flaw allowing attackers to upload arbitrary files and gain access to any user account.
2022-04-19 CVE-2018-6882 critical Synacor's Zimbra Collaboration Suite has a critical XSS vulnerability actively exploited by ransomware groups, demonstrating a failure to patch critical flaws promptly.
2026-03-18 CVE-2025-66376 high Synacor ZCS Classic UI XSS via CSS @import in email HTML is actively exploited and linked to ransomware campaigns.
2025-02-25 CVE-2023-34192 high Zimbra Collaboration Suite has an actively exploited XSS vulnerability allowing code execution via the autoSaveDraft function.
2026-04-20 CVE-2025-48700 high Synacor ZCS XSS vulnerability (CVE-2025-48700) allows arbitrary JavaScript execution in user sessions, enabling unauthorized access to sensitive data.
Open questions: Current patch cycle SLA for ZCS · Number of active ZCS deployments in DIB environments
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-17 04:17:19.559530+00:00