← CVE Tracker
7.2HIGHCISA KEV — actively exploited

CVE-2022-27925 — Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and…

Synacor · Zimbra Collaboration Suite · Published 21 Apr 2022 · Modified 1 Oct 2026

Description

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.

References

What to do
  1. Check whether Zimbra Collaboration Suite is in your asset inventory.
  2. Exploitation confirmed — patch within 72 hours.
  3. Record the decision in your risk register for audit evidence.
Alert me on similar CVEs →
Share

Link: adminadda.com/cve/CVE-2022-27925