CVE-2022-27925CISA KEVEPSS p99.9%

CVE-2022-27925Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability

Synacor / Zimbra Collaboration Suite (ZCS)

Description

Synacor Zimbra Collaboration Suite (ZCS) contains flaw in the mboximport functionality, allowing an authenticated attacker to upload arbitrary files to perform remote code execution. This vulnerability was chained with CVE-2022-37042 which allows for unauthenticated remote code execution.

Scoring

EPSS98.16% probability of exploitation · percentile 99.9% · 2026-06-16T12:03:06Z

CISA KEV entry

Added to KEV: 2022-08-11

(incoming)1

TypeTargetConfidenceTier
KEVEntrySynacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerabilitykev-cve-2022-279250%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
Synacor Zimbra Collaboration Suite (ZCS) Authentication Bypass Vulnerability
CVE
CVE-2022-41352
CVE
Synacor Zimbra Collaboration Suite (ZCS) Command Injection Vulnerability
CVE
Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability
CVE
Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
CVE
Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.