← CVE Tracker
7.5HIGHCISA KEV — actively exploited

CVE-2022-27924 — Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary…

Synacor · Zimbra Collaboration Suite · Published 21 Apr 2022 · Modified 2 Oct 2026

Description

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance. These memcache commands becomes unescaped, causing an overwrite of arbitrary cached entries.

References

What to do
  1. Check whether Zimbra Collaboration Suite is in your asset inventory.
  2. Exploitation confirmed — patch within 72 hours.
  3. Record the decision in your risk register for audit evidence.
Alert me on similar CVEs →
Share

Link: adminadda.com/cve/CVE-2022-27924