Zimbra vendor intelligence
Zimbra Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting Zimbra products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 18
- Known exploited vulnerabilities affecting Zimbra products
- In CISA KEV
- 17
- Records also listed in the official catalog
- Beyond CISA KEV
- 1
- Additional exploited CVEs absent from CISA KEV
- Sensor Observed
- 0
- Zimbra KEVs with sensor-observed exploitation activity
The catalog gap matters for Zimbra exposure
One of the eighteen exploited Zimbra CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 6% of this vendor portfolio.
- 94%
- Covered by CISA
- 6%
- Beyond CISA
- 5
- Product families
Attested Zimbra CVEs
Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2025-48700
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra... |
Zimbra Collaboration (ZCS) | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-66376
Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import... |
Collaboration | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2020-7796
Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled. |
Zimbra Collaboration Suite | Confirmed | In CISA | 28 May 2026 |
|
CVE-2025-68645
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper... |
Zimbra Collaboration (ZCS) | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-27915
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the... |
Zimbra Collaboration (ZCS) | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2019-9621
Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows... |
Zimbra Collaboration Suite | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2013-7091
Directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zimbra 7.2.2 and 8.0.2 allows... |
Zimbra Collaboration Suite | High | Beyond CISA | 05 Jun 2025 |
|
CVE-2024-27443
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature... |
Zimbra Collaboration (ZCS) | Confirmed | In CISA | 21 May 2025 |
|
CVE-2022-24682
An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild... |
Collaboration Suite | Confirmed | In CISA | 25 Feb 2022 |
|
CVE-2018-6882
Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1... |
Collaboration Suite | Confirmed | In CISA | 19 Apr 2022 |
|
CVE-2022-27924
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance.... |
Zimbra Collaboration | Confirmed | In CISA | 04 Aug 2022 |
|
CVE-2022-37042
Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing... |
Collaboration Suite | Confirmed | In CISA | 11 Aug 2022 |
|
CVE-2022-27925
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated... |
Collaboration | Confirmed | In CISA | 11 Aug 2022 |
|
CVE-2022-41352
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole... |
Collaboration | Confirmed | In CISA | 20 Oct 2022 |
|
CVE-2022-27926
A reflected cross-site scripting (XSS) vulnerability in the /public/launchNewWindow.jsp component of Zimbra Collaboration (aka ZCS) 9.0 allows... |
Collaboration | Confirmed | In CISA | 03 Apr 2023 |
|
CVE-2023-37580
Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client. |
Zimbra Collaboration | Confirmed | In CISA | 27 Jul 2023 |
|
CVE-2024-45519
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1... |
Zimbra Collaboration | Confirmed | In CISA | 03 Oct 2024 |
|
CVE-2023-34192
Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted script to... |
Zimbra Collaboration Suite | Confirmed | In CISA | 25 Feb 2025 |
No Zimbra CVEs match this search or filter.
Showing 18 of 18 Zimbra known exploited vulnerabilities.
Recurring weakness patterns
Neutralization, limitation, and server-side request forgery (ssrf) account for fourteen mapped occurrences across this Zimbra KEV portfolio.
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-918
Server-Side Request Forgery (SSRF)
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CWE-116
Improper Encoding or Escaping of Output
Early warning alerts
Get alerts on high-impact exploitation
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.