CyberMax
Home › Exploited CVEs › Synacor

Synacor Zimbra Collaboration Suite (ZCS) known exploited vulnerabilities, ranked

CISA KEV catalog 2026.10.02 · FIRST EPSS scores from 2026-10-02

CISA lists 16 Synacor Zimbra Collaboration Suite (ZCS) CVEs as exploited in the wild. 4 were added in the last 12 months and 5 are known to be used in ransomware. The table ranks all of them by EPSS, FIRST's estimate of the chance a CVE is exploited in the next 30 days, so the first rows are the ones to patch first.

Patch these first

All 16 Synacor Zimbra Collaboration Suite (ZCS) CVEs in CISA KEV, by EPSS

#CVEFlawEPSSRansomwareAddedFederal due
1CVE-2019-9670Zimbra Collaboration Suite (ZCS) Improper Restriction of XML External Entity Reference99.99%–2022-01-102022-07-10
2CVE-2024-45519Zimbra Collaboration Suite (ZCS) Command Execution99.91%–2024-10-032024-10-24
3CVE-2022-27925Zimbra Collaboration Suite (ZCS) Arbitrary File Upload98.7%Yes2022-08-112022-09-01
4CVE-2022-41352Zimbra Collaboration Suite (ZCS) Arbitrary File Upload95.5%Yes2022-10-202022-11-10
5CVE-2022-27924Zimbra Collaboration Suite (ZCS) Command Injection93.9%Yes2022-08-042022-08-25
6CVE-2022-37042Zimbra Collaboration Suite (ZCS) Authentication Bypass91.9%Yes2022-08-112022-09-01
7CVE-2019-9621Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF)81.0%–2025-07-072025-07-28
8CVE-2023-34192Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS)77.3%–2025-02-252025-03-18
9CVE-2023-37580Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS)49.1%–2023-07-272023-08-17
10CVE-2018-6882Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS)29.8%Yes2022-04-192022-05-10
11CVE-2024-27443Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS)23.6%–2025-05-192025-06-09
12CVE-2025-66376Zimbra Collaboration Suite (ZCS) Cross-Site Scripting20.2%–2026-03-182026-04-01
13CVE-2022-27926Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS)17.6%–2023-04-032023-04-24
14CVE-2026-73570Zimbra Collaboration Suite (ZCS) OS Command Injection11.7%–2026-08-212026-08-24
15CVE-2025-27915Zimbra Collaboration Suite (ZCS) Cross-site Scripting4.0%–2025-10-072025-10-28
16CVE-2025-48700Zimbra Collaboration Suite (ZCS) Cross-site Scripting1.7%–2026-04-202026-04-23
EPSS changes daily; a CVE with a low EPSS that is in KEV is still exploited somewhere. Federal due dates bind US federal civilian agencies; everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

More: all Synacor KEV CVEs · free KEV badge for Synacor · all vendors