CVE-2025-27915Active Exploitation(synacor / zimbra_collaboration_suite)

MEDIUMCVSS 5.4 · MEDIUMCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch synacor zimbra_collaboration_suite systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the Classic Web Client due to insufficient sanitization of HTML content in ICS files. When a user views an e-mail message containing a malicious ICS entry, its embedded JavaScript executes via an ontoggle event inside a <details> tag. This allows an attacker to run arbitrary JavaScript within the victim's session, potentially leading to unauthorized actions such as setting e-mail filters to redirect messages to an attacker-controlled address. As a result, an attacker can perform unauthorized actions on the victim's account, including e-mail redirection and data exfiltration.

5.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-10-28. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-79

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • zimbra_collaboration_suite

Threat summary

  • Active exploitation appears in 4 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 3 observed days

What's happening

  • Active exploitation reported across 4 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Peaked 1d ago at 2 mentions (2026-07-24); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
zimbra_collaboration_suite

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-26: 1Mentions · 2026-07-24: 2Mentions · 2026-09-10: 1PoC Mentioned / Linked · 2026-07-24: 1Active Exploitation · 2026-03-26: 1Active Exploitation · 2026-07-24: 2Active Exploitation · 2026-09-10: 1Patch / Workaround · 2026-07-24: 1Patch / Workaround · 2026-09-10: 1Technical Details · 2026-03-26: 1Technical Details · 2026-07-24: 2Technical Details · 2026-09-10: 103-2607-2409-10
Signal classification1 categories
Active Exploitation
4100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-261
Active Exploitation1
2026-07-242
Active Exploitation2
2026-09-101
Active Exploitation1
Full discourse4 posts
  • blackorbird@blackorbird
    Active Exploitation

    TA488(Void Blizzard、Laundry Bear) Targets Zimbra Mailservers with Half-Click Exploits https://www.proofpoint.com/us/blog/threat-insight/ta488-targets-zimbra-mailservers-half-click-exploits Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days from TA458 CVE-2025-27915: Zimbra (zero-day) CVE-2025-3929: mDaemon (zero-day) CVE-2023-43770: Roundcube (n-day) CVE-2024-42009: Roundcube (n-day) CVE-2026- 8496: SOGo (zero-day) https://www.proofpoint.com/us/blog/threat-insight/ta458-roundpress-exploits

    Post summary

    The snippet highlights several zero‑day and older vulnerabilities (e.g., CVE‑2025‑27915, CVE‑2025‑3929) being actively exploited by TA488 and TA458 groups, with Proofpoint blogs providing evidence and contextual details. However, no specific patches, tool code, or false‑positive claims are mentioned.

    0813299.1K
    43.8K followersView on X
  • Nobuyoshi Sato@7n2jju
    Active Exploitation

    Zimbra の脆弱性 CVE-2025-27915:iCalendar ファイルを介した XSS 攻撃の痕跡が発見される – IoT OT Security News https://iototsecnews.jp/2025/10/05/hackers-exploited-zimbra-flaw-as-zero-day-using-icalendar-files/ これとは違うなあ。HTMLコンテンツは入っていなかった。

    Post summary

    The report confirms that CVE‑2025‑27915 was actively exploited as a zero‑day XSS vulnerability via iCalendar files in the wild, but no specific PoC, patch, or tool details are disclosed.

    00010240
    1.3K followersView on X
  • @pedri77@pedri77
    Active Exploitation

    A now patched security vulnerability in Zimbra Collaboration was exploited as a zero-day earlier this year in cyber attacks targeting the Brazilian military. Tracked as CVE-2025-27915 (CVSS score: 5.4), the vulnerabilit... https://f.mtr.cool/ld2p80a688

    Post summary

    CVE-2025-27915, a zero‑day in Zimbra Collaboration, was actively exploited against the Brazilian military earlier this year, but it has since been patched; no PoC or exploit code details are provided.

    0000090
    2.1K followersView on X
  • Cephas@Cephas_PM
    Active Exploitation

    new zimbra cve in the wild CVE-2025-27915, which was exploited in the wild using a malicious ICS file to execute arbitrary Js in users sessions CVE-2026-33372 is a crosssite request forgery vuln act fast and patch the govt zimbra servers ama someone will h... @ICTAuthorityKE

    Post summary

    CVE-2025-27915 is actively exploited in the wild via a malicious file that runs arbitrary JavaScript in user sessions, while CVE-2026-33372 presents a CSRF issue; immediate patching of Zimbra servers is urged.

    0000057
    17 followersView on X
CPE platform detail46 entries

46 of 46 entries

PartVendorProductVersionTarget SWTarget HW
Appsynacorzimbra_collaboration_suite---
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--

Explore more