CVE-2022-27925

HIGH7.2Published on April 21, 2022

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.

Actively exploited

  • In the CISA exploited-vulnerabilities catalogue since Aug 11, 2022
  • US federal agencies must remediate it by Sep 1, 2022 (BOD 22-01)
  • First attack observed 112 days after disclosure
  • Confirmed by sensors, not only by reports
  • Used in ransomware campaigns

Apply updates per vendor instructions.

Source: CISA KEV · Aug 21, 2026 Aug 20, 2026 Aug 5, 2026 Aug 1, 2026 Jul 30, 2026 Jul 28, 2026

CVSS score7.2 / 10CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness type (CWE)CWE-22, CWE-22
Vendorssynacor

Affected products

VendorsProdottoVersioni
synacorzimbra collaboration suite8.8.15

Related articles

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE database