CVE-2022-27925
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.
Actively exploited
- In the CISA exploited-vulnerabilities catalogue since Aug 11, 2022
- US federal agencies must remediate it by Sep 1, 2022 (BOD 22-01)
- First attack observed 112 days after disclosure
- Confirmed by sensors, not only by reports
- Used in ransomware campaigns
Apply updates per vendor instructions.
Source: CISA KEV · Aug 21, 2026 Aug 20, 2026 Aug 5, 2026 Aug 1, 2026 Jul 30, 2026 Jul 28, 2026
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HAffected products
| Vendors | Prodotto | Versioni |
|---|---|---|
| synacor | zimbra collaboration suite | 8.8.15 |
Related articles
VulnerabilitiesZimbra CVE-2026-73570 Exploited in the Wild: Who Needs to Patch Immediately
CVE-2026-73570 in Zimbra Collaboration is actively exploited. Learn who needs to patch immediately, the vulnerability details, and security steps.
APTSPECTRE, the backdoor that disables EDRs: inside UAT-10147's arsenal
Recently, Cisco Talos published a two-part analysis of the Chinese-speaking group UAT-10147 , which is active against Windows and Linux web servers on a
This product uses the NVD API but is not endorsed or certified by the NVD.