Zimbra vendor intelligence

Zimbra Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting Zimbra products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Browse Zimbra KEVs Full KEV feed
Total KEVs
18
Known exploited vulnerabilities affecting Zimbra products
In CISA KEV
17
Records also listed in the official catalog
Beyond CISA KEV
1
Additional exploited CVEs absent from CISA KEV
Sensor Observed
0
Zimbra KEVs with sensor-observed exploitation activity

The catalog gap matters for Zimbra exposure

One of the eighteen exploited Zimbra CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 6% of this vendor portfolio.

94%
Covered by CISA
6%
Beyond CISA
5
Product families

Attested Zimbra CVEs

Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2025-48700

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra...

Zimbra Collaboration (ZCS) Confirmed In CISA 01 Jun 2026
CVE-2025-66376

Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import...

Collaboration Confirmed In CISA 01 Jun 2026
CVE-2020-7796

Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled.

Zimbra Collaboration Suite Confirmed In CISA 28 May 2026
CVE-2025-68645

A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper...

Zimbra Collaboration (ZCS) Confirmed In CISA 01 Jun 2026
CVE-2025-27915

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the...

Zimbra Collaboration (ZCS) Confirmed In CISA 01 Jun 2026
CVE-2019-9621

Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows...

Zimbra Collaboration Suite Confirmed In CISA 01 Jun 2026
CVE-2013-7091

Directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zimbra 7.2.2 and 8.0.2 allows...

Zimbra Collaboration Suite High Beyond CISA 05 Jun 2025
CVE-2024-27443

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature...

Zimbra Collaboration (ZCS) Confirmed In CISA 21 May 2025
CVE-2022-24682

An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild...

Collaboration Suite Confirmed In CISA 25 Feb 2022
CVE-2018-6882

Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1...

Collaboration Suite Confirmed In CISA 19 Apr 2022
CVE-2022-27924

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance....

Zimbra Collaboration Confirmed In CISA 04 Aug 2022
CVE-2022-37042

Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing...

Collaboration Suite Confirmed In CISA 11 Aug 2022
CVE-2022-27925

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated...

Collaboration Confirmed In CISA 11 Aug 2022
CVE-2022-41352

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole...

Collaboration Confirmed In CISA 20 Oct 2022
CVE-2022-27926

A reflected cross-site scripting (XSS) vulnerability in the /public/launchNewWindow.jsp component of Zimbra Collaboration (aka ZCS) 9.0 allows...

Collaboration Confirmed In CISA 03 Apr 2023
CVE-2023-37580

Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client.

Zimbra Collaboration Confirmed In CISA 27 Jul 2023
CVE-2024-45519

The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1...

Zimbra Collaboration Confirmed In CISA 03 Oct 2024
CVE-2023-34192

Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted script to...

Zimbra Collaboration Suite Confirmed In CISA 25 Feb 2025

Showing 18 of 18 Zimbra known exploited vulnerabilities.

Recurring weakness patterns

Neutralization, limitation, and server-side request forgery (ssrf) account for fourteen mapped occurrences across this Zimbra KEV portfolio.

Browse all KEVs →

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.