CVE-2020-7796Active Exploitation(synacor / zimbra_collaboration_suite)

MEDIUMCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch synacor zimbra_collaboration_suite systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled.

4.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-03-10. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-918

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • zimbra_collaboration_suite

Threat summary

  • Active exploitation appears in 10 classified signals
  • Patch or workaround signal is available
  • 12 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 10 signals
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 10 signals
  • Disclosure: 1 classified signal
  • Peaked 4d ago at 5 mentions (2026-02-18); latest day: 1
  • 12 total mentions across 6 days

Affected systems

Vendors
Products
zimbra_collaboration_suite

1 version affected across 1 product

Deep dive

Activity timeline12 mentions / 6d
01345Mentions · 2026-02-17: 1Mentions · 2026-02-18: 5Mentions · 2026-02-19: 1Mentions · 2026-02-20: 3Mentions · 2026-04-11: 1Mentions · 2026-07-03: 1Active Exploitation · 2026-02-18: 5Active Exploitation · 2026-02-19: 1Active Exploitation · 2026-02-20: 3Active Exploitation · 2026-04-11: 1Patch / Workaround · 2026-02-18: 3Patch / Workaround · 2026-02-19: 1Technical Details · 2026-02-17: 1Technical Details · 2026-02-18: 5Technical Details · 2026-02-20: 2Technical Details · 2026-04-11: 1Technical Details · 2026-07-03: 102-1702-1802-1902-2004-1107-03
Signal classification3 categories
Active Exploitation
1083.3%
Disclosure
18.3%
Patch
18.3%
Referenced assets13 URLs
Classification over time
DateTotalLabels
2026-02-171
Disclosure1
2026-02-185
Active Exploitation5
2026-02-191
Active Exploitation1
2026-02-203
Active Exploitation3
2026-04-111
Active Exploitation1
2026-07-031
Patch1
Full discourse12 posts
  • Dark Web Informer@DarkWebInformer
    Disclosure

    ‼️ CISA has added 4 vulnerabilities to the KEV Catalog https://darkwebinformer.com/cisa-kev-catalog/ CVE-2020-7796: Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability CVE-2024-7694: TeamT5 ThreatSonar Anti-Ransomware Unrestricted Upload of File with Dangerous Type Vulnerability CVE-2008-0015: Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability CVE-2026-2441: Google Chromium CSS Use-After-Free Vulnerability

    Post summary

    CISA announced the addition of four CVEs to its KEV catalog, providing only the CVE identifiers and brief vulnerability descriptions without any mention of exploitation, patches, or PoC details.

    1702484.0K
    162.9K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(2/17追加) 🛡️No.1520 CVE-2020-7796 Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability ============= CVSSスコア: 9.8 (Base) / CISA-ADP CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 種別:サーバサイドのリクエストフォージェリ (CWE-918 / CISA-ADP) 深刻度:緊急🔥 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、WebEx zimlet がインストールされ、zimlet JSP が有効になっている場合、リモートからSSRFの脆弱性の影響を受ける恐れがあります。 https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.15/P7 🛡️No.1521 CVE-2024-7694 TeamT5 ThreatSonar Anti-Ransomware Unrestricted Upload of File with Dangerous Type Vulnerability ============= CVSSスコア: 7.2 (Base) / TWCERT/CC CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H 種別:危険なタイプのファイルの無制限アップロード (CWE-434/ TWCERT/CC) 深刻度:重要 ---------------------- 悪用時影響: 製品プラットフォームの管理者権限を持つ攻撃者により、リモートから悪意のあるファイルをアップロードし、サーバー上で任意のシステムコマンドを実行される恐れがあります。 https://teamt5.org/en/posts/vulnerability-notice-threat-sonar-anti-ransomware-20240715/ https://www.twcert.org.tw/en/cp-139-8000-e5a5c-2.html 🛡️No.1522 CVE-2008-0015 Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability ============= CVSSスコア: 8.8 (Base) / CISA-ADP CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 種別:スタックベースのバッファオーバーフロー (CWE-121/ CISA-ADP) 深刻度:重要 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、特別に細工されたWeb ページを介して、閲覧したユーザーの権限でコード実行される恐れがあります。 https://web.archive.org/web/20110305211119/https://www.microsoft.com/technet/security/bulletin/ms09-032.mspx 🛡️No.1523 CVE-2026-2441 Google Chromium CSS Use-After-Free Vulnerability ============= CVSSスコア: 8.8 (Base) / CISA-ADP CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 種別:解放済みメモリの使用 (CWE-416/ CISA-ADP) 深刻度:重要 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、特別に細工されたHTML ページを介して、ヒープ破壊を行う恐れがあります。この脆弱性は、Google Chrome、Microsoft Edge、Opera など、Chromium を利用する複数のウェブブラウザに影響を与える可能性があります。 https://chromereleases.googleblog.com/2026/02/stable-channel-update-for-desktop_13.html CISA Adds Four Known Exploited Vulnerabilities to Catalog https://www.cisa.gov/news-events/alerts/2026/02/17/cisa-adds-four-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    CISA has added four CVEs—CVE-2020-7796, CVE-2024-7694, CVE-2008-0015, and CVE-2026-2441—to its Known Exploited Vulnerabilities catalog, providing technical details and links to vendor patches.

    010814.3K
    42.5K followersView on X
  • DC3 DCISE@DC3DCISE
    Patch

    🚨 CISA adds 4 flaws to the KEV. Prioritize patching: 🌐 Chrome: CVE-2026-2441 (UAF, RCE) 🛡️ TeamT5 ThreatSonar: CVE-2024-7694 (File Upload) 📧 Zimbra: CVE-2020-7796 (SSRF) 💻 Windows: CVE-2008-0015 (ActiveX RCE) #Patching #KEV #VulnerabilityManagement #InfoSec #DCISEWarning

    Post summary

    CISA has added four CVEs to the KEV and urges security teams to prioritize patching for Chrome, TeamT5 ThreatSonar, Zimbra, and Windows.

    01011501
    729 followersView on X
  • CTIWatch@ctiwatchcloud
    Active Exploitation

    🚨 [CRITICAL] Active exploitation detected: CVE-2020-7796 Exploit in the wild confirmed for CVE-2020-7796 (CVSS 9.8). Synacor Zimbra Collaboration Suite (ZCS) contains a server-side request forgery vulnerabil... 🔗 http://ctiwatch.cloud/alerts #ZeroDay #ExploitInWild #CyberSecurity

    Post summary

    The post declares that CVE-2020-7796—a server‑side request forgery in Synacor Zimbra Collaboration Suite—has been actively exploited in the wild with a CVSS score of 9.8, but offers no PoC, exploit code, or patch details.

    0001091
    5.6K followersView on X
  • サイバーセキュリティニュース-JP@cybersecnews_jp
    Active Exploitation

    CISAが4つの既知の脆弱性をカタログに追加 https://www.cisa.gov/news-events/alerts/2026/02/17/cisa-adds-four-known-exploited-vulnerabilities-catalog CVE-2008-0015 Microsoft Windows ビデオ ActiveX コントロールのリモート コード実行の脆弱性 CVE-2020-7796 Synacor Zimbra Collaboration Suite (ZCS) のサーバー側リクエストフォージェリ脆弱性

    Post summary

    CISA added two CVEs to its catalog of known exploited vulnerabilities, confirming they have been used in the wild, but the post does not provide PoC, exploit code, or patch details.

    1000062
    44 followersView on X
  • キタきつね@foxbook
    Active Exploitation

    CISAが4つの既知の脆弱性をカタログに追加 CISA Adds Four Known Exploited Vulnerabilities to Catalog #CISA (Feb 17) CVE-2008-0015 Microsoft Windows ビデオ ActiveX コントロールのリモート コード実行の脆弱性 CVE-2020-7796 Synacor Zimbra Collaboration Suite (ZCS) のサーバー側リクエストフォージェリ脆弱性 CVE-2024-7694 TeamT5 ThreatSonar Anti-Ransomware の危険な種類のファイルの無制限アップロードの脆弱性 CVE-2026-2441 Google Chromium CSS の解放後使用の脆弱性 https://www.cisa.gov/news-events/alerts/2026/02/17/cisa-adds-four-known-exploited-vulnerabilities-catalog

    Post summary

    CISA announced that four CVEs—CVE-2008-0015, CVE-2020-7796, CVE-2024-7694, and CVE-2026-2441—are known to be exploited in the wild, providing brief technical details but no PoC or patch information.

    00010245
    4.7K followersView on X
  • twelvesec@twelvesec
    Active Exploitation

    #CISA added four #security flaws (CVE-2026-2441, CVE-2024-7694, CVE-2020-7796, CVE-2008-0015) to its KEV catalogue, citing evidence of active exploitation in the wild. #CyberSecurity #InfoSec https://ift.tt/rAiQ0MN https://t.co/W1h3dmwdH7

    Post summary

    CISA added four CVEs to its KEV catalogue, citing evidence of active exploitation in the wild. The tweet highlights ongoing real-world usage of the vulnerabilities.

    0000083
    1.5K followersView on X
  • Dr. John D. Johnson@johndjohnson
    Active Exploitation

    CISA Flags Four Security Flaws Under Active Exploitation in Latest KEV Update - CVE-2026-2441 (CVSS score: 8.8) - A use-after-free vulnerability in Google Chrome - CVE-2024-7694 (CVSS score: 7.2) - An arbitrary file upload vulnerability in TeamT5 ThreatSonar - CVE-2020-7796 (CVSS score: 9.8) - A server-side request forgery (SSRF) vulnerability in Synacor Zimbra Collaboration Suite - CVE-2008-0015 (CVSS score: 8.8) - A stack-based buffer overflow vulnerability in Microsoft Windows Video ActiveX Control https://nuel.ink/MhJU0b

    Post summary

    The text reports that four CVEs are actively exploited in the wild, as flagged by CISA.

    0000082
    1.1K followersView on X
  • ThreatSynop@ThreatSynop
    Active Exploitation

    🚨 CISA Adds Actively Exploited Chrome, Zimbra, Windows ActiveX, and ThreatSonar Flaws to KEV CISA updated its Known Exploited Vulnerabilities (KEV) catalog with four issues—Chrome UAF (CVE-2026-2441), Zimbra SSRF (CVE-2008-0015), Windows Video ActiveX Control (CVE-2020-7796), and TeamT5 ThreatSonar (CVE-2024-7694)—noting confirmed exploitation for at least Chrome and broad scanning/exploitation activity for the Windows flaw. This matters because KEV inclusion is a high-confidence “patch-now” signal and these bugs can enable RCE/credentialed footholds leading to malware delivery (e.g., Dogkild worm) and deeper compromise. 🕷️ Malware: Dogkild worm (mentioned) 🎯 Target: Global/Enterprise + Government #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://www.scworld.com/brief/updated-cisa-vulnerabilities-catalog-adds-chrome-zimbra-windows-threatsonar-flaws

    Post summary

    CISA has added several CVEs to its KEV catalog, confirming active exploitation for some (notably Chrome and Windows ActiveX) and urging urgent patching of these vulnerabilities.

    00000109
    174 followersView on X
  • Darknetbreaker@Tejaskumar172
    Active Exploitation

    🚨 CISA: 4 vulnerabilities under ACTIVE exploitation. • Chrome CVE-2026-2441 • Zimbra CVE-2020-7796 • ThreatSonar file upload flaw • Windows ActiveX (2008) Real attacks happening now. Patch before March 10. #CyberSecurity #Infosec #CISA #zeroday https://t.co/rtc34WstWW

    Post summary

    CISA alerts that four CVEs are actively exploited in the wild and urges users to patch before March 10.

    0000076
    3 followersView on X
  • ThreatSynop@ThreatSynop
    Active Exploitation

    🚨 CISA Flags 4 Actively Exploited Bugs: Chrome CSS Zero-Day, Windows ActiveX RCE, Zimbra SSRF, ThreatSonar Upload Flaw CISA added four vulnerabilities to its KEV catalog—CVE-2026-2441 (Chrome/Chromium CSS UAF, exploited in the wild), CVE-2008-0015 (Windows Video ActiveX/DirectShow RCE), CVE-2020-7796 (Zimbra ZCS SSRF), and CVE-2024-7694 (TeamT5 ThreatSonar arbitrary file upload that can enable server-side command execution)—and ordered U.S. federal agencies to remediate by March 10, 2026. This matters because KEV inclusion indicates real-world exploitation risk and sets an urgent patch/mitigation clock for both public and private-sector defenders running affected stacks. 🎯 Target: USA/Government (FCEB) + Global/Enterprise #️⃣ Category: #Vulnerability #BlueTeam #CyberLaw 🔗 URL: https://securityaffairs.com/188163/uncategorized/u-s-cisa-adds-google-chromium-css-microsoft-windows-teamt5-threatsonar-anti-ransomware-and-zimbra-flaws-to-its-known-exploited-vulnerabilities-catalog.html

    Post summary

    CISA’s KEV inclusion confirms that CVE‑2026‑2441, CVE‑2008‑0015, CVE‑2020‑7796, and CVE‑2024‑7694 are actively exploited, prompting an urgent patch timeline for affected systems.

    0000061
    176 followersView on X
  • ThreatSynop@ThreatSynop
    Active Exploitation

    🚨 CISA Flags 4 Actively Exploited Bugs (Chrome, Zimbra, Windows ActiveX, ThreatSonar) — Patch Now CISA added four vulnerabilities to the KEV catalog: Chrome UAF CVE-2026-2441, TeamT5 ThreatSonar file-upload RCE CVE-2024-7694, Zimbra SSRF CVE-2020-7796, and Windows Video ActiveX RCE CVE-2008-0015, indicating in-the-wild exploitation and requiring rapid remediation (FCEB deadline: March 10, 2026). This update matters because it spans browser, email, endpoint, and security tooling—raising compromise likelihood for orgs that lag on patching and increasing urgency for detection/hunting around exploit attempts. 🎯 Target: Global/All Sectors #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://thehackernews.com/2026/02/cisa-flags-four-security-flaws-under.html

    Post summary

    CISA has identified four vulnerabilities that are actively exploited in the wild, urging organizations to patch immediately.

    0000079
    176 followersView on X
CPE platform detail8 entries

8 of 8 entries

PartVendorProductVersionTarget SWTarget HW
Appsynacorzimbra_collaboration_suite---
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--

Explore more