CVE-2025-48700Active Exploitation(synacor / zimbra_collaboration_suite)

HIGHCVSS 6.1 · MEDIUMCISA KEV

Exploitation observed; activity peaked at 7 mentions and remains active

Immediate actions

  • Patch synacor zimbra_collaboration_suite systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Classic UI allows attackers to execute arbitrary JavaScript within the user's session, potentially leading to unauthorized access to sensitive information. This issue arises from insufficient sanitization of HTML content, specifically involving crafted tag structures and attribute values that include an @import directive and other script injection vectors. The vulnerability is triggered when a user views a crafted e-mail message in the Classic UI, requiring no additional user interaction.

7.8/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-04-23. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-79

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • zimbra_collaboration_suite

Threat summary

  • Active exploitation appears in 18 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 25 mentions across 9 observed days

What's happening

  • Active exploitation reported across 18 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 9 signals
  • Technical details provided in 15 signals
  • General: 4 classified signals
  • Disclosure: 2 classified signals
  • Peaked 4d ago at 7 mentions (2026-04-24); latest day: 1
  • 25 total mentions across 9 days

Affected systems

Vendors
Products
zimbra_collaboration_suite

2 versions affected across 1 product

Deep dive

Activity timeline25 mentions / 9d
02457Mentions · 2026-04-20: 2Mentions · 2026-04-21: 5Mentions · 2026-04-22: 4Mentions · 2026-04-23: 1Mentions · 2026-04-24: 7Mentions · 2026-04-25: 3Mentions · 2026-04-27: 1Mentions · 2026-04-29: 1Mentions · 2026-05-19: 1PoC Mentioned / Linked · 2026-04-22: 1PoC Mentioned / Linked · 2026-04-27: 1Exploit Tool / Code · 2026-04-27: 1Active Exploitation · 2026-04-20: 1Active Exploitation · 2026-04-21: 4Active Exploitation · 2026-04-22: 2Active Exploitation · 2026-04-23: 1Active Exploitation · 2026-04-24: 6Active Exploitation · 2026-04-25: 2Active Exploitation · 2026-04-27: 1Active Exploitation · 2026-05-19: 1Patch / Workaround · 2026-04-21: 1Patch / Workaround · 2026-04-22: 3Patch / Workaround · 2026-04-24: 4Patch / Workaround · 2026-05-19: 1Technical Details · 2026-04-20: 1Technical Details · 2026-04-21: 5Technical Details · 2026-04-22: 3Technical Details · 2026-04-24: 4Technical Details · 2026-04-25: 1Technical Details · 2026-05-19: 104-2004-2104-2204-2304-2404-2504-2704-2905-19
Signal classification4 categories
Active Exploitation
1872.0%
General
416.0%
Disclosure
28.0%
Patch
14.0%
Referenced assets33 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-202
Active Exploitation1General1
2026-04-215
Active Exploitation4General1
2026-04-224
Active Exploitation2Disclosure2
2026-04-231
Active Exploitation1
2026-04-247
Active Exploitation6Patch1
2026-04-253
Active Exploitation2General1
2026-04-271
Active Exploitation1
2026-04-291
General1
2026-05-191
Active Exploitation1
Full discourse20 posts
  • The Shadowserver Foundation@Shadowserver
    Active Exploitation

    We are scanning/reporting daily Zimbra Collaboration Suite instances vulnerable to CVE-2025-48700, that can allow unauthorized access to sensitive information. This vulnerability is exploited in the wild and on @CISACyber KEV. We see over 10.5K IPs unpatched 2026-04-23. https://t.co/k0rRxE0ecV

    Post summary

    The post confirms that CVE-2025‑48700 is actively exploited in the wild, with over 10.5K vulnerable Zimbra instances unpatched, underscoring an immediate need for remediation.

    150612.1K
    21.9K followersView on X
  • Teegra 🧝‍♀️𝕏@Teeegra
    Active Exploitation

    بیش از ۱۰,۵۰۰ نمونه از نرم‌افزار همکاری زیمبرا (Zimbra Collaboration Suite) که در اینترنت در معرض دسترسی عموم قرار دارند، در برابر حملاتی که از یک آسیب‌پذیری اسکریپت‌نویسی متقاطع (cross-site scripting/XSS) با شناسه CVE-2025-48700 بهره‌برداری می‌کنند، این آسیب‌پذیری به مهاجمان احراز هویت‌نشده اجازه می‌دهد پس از اجرای کد جاوااسکریپت به اطلاعات حساس دسترسی پیدا کنند. آژانس امنیت سایبری آمریکا (CISA) این آسیب‌پذیری را به فهرست آسیب‌پذیری‌های شناخته‌شده مورد بهره‌برداری (KEV) افزوده و به نهادهای فدرال دستور داده است ظرف سه روز، تا ۲۳ آوریل، سرورهای زیمبرا خود را ایمن‌سازی کنند. آسیب‌پذیری‌های زیمبرا پیش‌تر نیز هدف گروه‌های هکری دولتی روسیه بوده‌اند؛ گروه APT28 (معروف به Fancy Bear) از یک نقص مشابه XSS برای حملات فیشینگ علیه نهادهای دولتی اوکراین بهره برده است.

    Post summary

    CISA has listed CVE‑2025‑48700 as a known exploited vulnerability, indicating active exploitation of a cross‑site scripting flaw in Zimbra Collaboration Suite; federal agencies are required to remediate within three days.

    0001011.6K
    19.0K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(4/20追加) 🛡️No.1571 CVE-2026-20122 Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability ✅概要 ・深刻度:重要 7.1 (CVSS Base) / Cisco Systems, Inc. (CNA) ・種別:特権 API の不適切な使用 (CWE-648) ・CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Cisco Catalyst SD-WAN Manager の API において、認証されたリモートの攻撃者がローカルファイルシステム上の任意のファイルを上書きできる脆弱性。悪用には影響を受けるシステムに対する API アクセス権を持つ有効な読み取り専用資格情報が必要。事前認証されていない攻撃者により、任意ファイルの上書きに加え、vmanage ユーザー権限を取得される恐れがある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:中 ________________________________________ ✅攻撃前提条件 ・Cisco Catalyst SD-WAN Manager の脆弱バージョンが稼働していること。 ・攻撃者が対象システムへネットワーク越しに到達可能であること。 ・攻撃者が API アクセス権を持つ有効な読み取り専用資格情報を有していること。 ________________________________________ ✅悪用時影響 ・ローカルファイルシステム上の任意のファイルを上書き ・vmanage ユーザー権限を取得 ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:確認済み。Cisco PSIRT は、2026年3月に、CVE-2026-20128 および CVE-2026-20122 の悪用を把握したと報告。 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2026-20122 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v https://www.cisa.gov/news-events/directives/ed-26-03-mitigate-vulnerabilities-cisco-sd-wan-systems https://www.cisa.gov/news-events/directives/supplemental-direction-ed-26-03-hunt-and-hardening-guidance-cisco-sd-wan-systems 🛡️No.1572 CVE-2026-20133 Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability ✅概要 ・深刻度:重要 7.5 (CVSS Base) / NVD ・種別:情報漏えい (CWE-200) ・CVSS: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Cisco Catalyst SD-WAN Manager において、事前認証されていない攻撃者により、機密情報を摂取される恐れがある。原因はファイルシステムのアクセス制限が不十分なためで、攻撃者は対象システムのAPIにアクセスして悪用。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:低 ________________________________________ ✅攻撃前提条件 ・Cisco Catalyst SD-WAN Manager の脆弱バージョンが稼働していること。 ・攻撃者が対象システムへネットワーク越しに到達可能であること。 ・認証は不要。 ________________________________________ ✅悪用時影響 ・該当システム上の機密情報を閲覧 ・基盤となるオペレーティングシステム上の機密情報を読み取られる ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:公開情報確認できず ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2026-20133 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v 🛡️No.1573 CVE-2025-2749 Kentico Xperience Path Traversal Vulnerability ✅概要 ・深刻度:重要 7.2 (CVSS Base) / VulnCheck (CNA) ・種別:パス・トラバーサル、 危険なタイプのファイルの無制限アップロード(CWE-22,CWE-434) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H (NVD) Kentico Xperience 13.0.178以前に、認証済の攻撃者によって、Staging Sync Server経由で任意の相対パスへデータをアップロード可能な脆弱性が存在。パストラバーサルと任意ファイルアップロードを経てサーバサイドで実行可能なコンテンツ配置によるリモートコード実行を行われる恐れがある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ________________________________________ ✅攻撃前提条件 ・Kentico Xperience 13.0.177以前が稼働していること。 ・Staging Serviceが有効であること。 ・Staging Serviceがユーザー名/パスワード認証で構成されていること。 ・攻撃者がStaging Sync Serverに対する有効な認証済み権限を有すること。 ________________________________________ ✅悪用時影響 ・任意ファイルアップロードにより、サーバサイドで実行可能なコンテンツを配置 ・リモートコードの実行 ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:未確認 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-2749 https://devnet.kentico.com/download/hotfixes 🛡️No.1574 CVE-2023-27351 PaperCut NG/MF Improper Authentication Vulnerability ✅概要 ・深刻度:重要 8.2 (CVSS Base) / NVD ・種別:不適切な認証 (CWE-287) ・CVSS: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N PaperCut NG/MFのApplication Serverにおいて、事前認証されていない攻撃者により、リモートからユーザー情報を取得される恐れがある。対象となる情報に、PaperCutは、ユーザー名、氏名、メールアドレス、部署情報、カード番号に加え、内部作成ユーザーのハッシュ化パスワードを取得され得ると報告。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ________________________________________ ✅攻撃前提条件 ・PaperCut NG/MFのApplication Serverが脆弱バージョンで稼働していること。 ・攻撃者が対象サーバへネットワーク越しに到達可能であること。 ・認証は不要。 ________________________________________ ✅悪用時影響 ・認証を回避して、ユーザー名、氏名、メールアドレス、部署情報、カード番号などのユーザー情報を取得 ・内部作成ユーザーに限り、ハッシュ化されたパスワードを取得 ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず (GitHub) ・ITW:未確認 (PaperCut) ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2023-27351 https://www.papercut.com/kb/Main/PO-1216-and-PO-1219 🛡️No.1575 CVE-2025-48700 Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability ✅概要 ・深刻度:注意6.1 (CVSS Base) / CISA-ADP ・種別:クロスサイトスクリプティング (CWE-79) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Zimbra Collaboration (ZCS) 8.8.15、9.0、10.0、10.1 の Classic UI において、HTMLコンテンツの不十分なサニタイズにより、ユーザーのセッション内で任意のJavaScriptを実行される恐れがある。細工されたタグ構造や属性値に含まれる @ import ディレクティブなどのスクリプト注入ベクトルが原因。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ________________________________________ ✅攻撃前提条件 ・Zimbra Collaboration (ZCS) 8.8.15、9.0、10.0、10.1 の脆弱バージョンが稼働していること。 ・攻撃者が細工した電子メールメッセージを対象ユーザーに閲覧させること。 ・Classic UI で細工された電子メールメッセージが閲覧されること。 ・追加の利用者操作は不要。 ________________________________________ ✅悪用時影響 ・ユーザーのセッション内で任意のJavaScriptを実行 ・機微情報への不正アクセスにつながる ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-48700 https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories 🛡️No.1576 CVE-2026-20128 Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability ✅概要 ・深刻度:重要 7.5 (CVSS Base) / Cisco Systems, Inc. (CNA) ・種別:復元可能な形式でのパスワード保存 (CWE-257) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Cisco Catalyst SD-WAN Manager の Data Collection Agent(DCA)機能において、事前認証されていない攻撃者により、リモートから DCA ユーザー権限を取得される恐れがある。影響を受けるシステム上に DCA ユーザーの認証情報ファイルが存在することで、細工された HTTP 要求により当該ファイルを読み取られる可能性。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:低 ________________________________________ ✅攻撃前提条件 ・Cisco Catalyst SD-WAN Manager の脆弱バージョンが稼働していること。 ・攻撃者が対象システムへネットワーク越しに到達可能であること。 ・認証は不要。 ________________________________________ ✅悪用時影響 ・DCA パスワードを含むファイルを読み取られる ・別の影響を受けるシステムへアクセスされ、DCA ユーザー権限を取得される ・機密情報へアクセスされる ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み。Cisco PSIRT は、2026年3月に、CVE-2026-20128 および CVE-2026-20122 の悪用を把握したと報告。 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2026-20128 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v   🛡️No.1577 CVE-2025-32975 Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability ✅概要 ・深刻度:緊急 10.0 (CVSS Base) / CISA-ADP ・種別:不適切な認証 (CWE-287) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Quest KACE Systems Management Appliance (SMA) には、事前認証されていない攻撃者により、正規ユーザーになりすませる認証回避の脆弱性が存在。SSO認証処理に起因し他脆弱性で、完全な管理者乗っ取りをされる恐れがある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ________________________________________ ✅攻撃前提条件 ・Quest KACE Systems Management Appliance (SMA) の脆弱バージョンが稼働していること。 ・対象機器がネットワーク越しに到達可能であること。 ・認証は不要。 ________________________________________ ✅悪用時影響 ・正当な認証情報なしに正規ユーザーになりすまされる ・完全な管理者権限を取得される ・アプライアンスを全面的に掌握される ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:確認済み。Arctic Wolf は、2026年3月9日の週から、インターネット公開された未パッチのKACE SMAに対するCVE-2025-32975悪用の可能性がある不正活動を顧客環境で観測したと報告。 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-32975 https://support.quest.com/kb/4379499/quest-response-to-kace-sma-vulnerabilities-cve-2025-32975-cve-2025-32976-cve-2025-32977-cve-2025-32978 🛡️No.1578 CVE-2024-27199 JetBrains TeamCity Relative Path Traversal Vulnerability ✅概要 ・深刻度:重要 7.3 (CVSS Base) / JetBrains s.r.o. (CNA) (NVD) ・種別:相対パストラバーサル (CWE-23) (NVD) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L (NVD) JetBrains TeamCity 2023.11.4未満に相対パストラバーサルの脆弱性が存在。事前認証されていない攻撃者により、HTTP(S)経由で認証チェックを回避し、TeamCityサーバの管理権限を取得される恐れがある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ________________________________________ ✅攻撃前提条件 ・TeamCity On-Premises 2023.11.3以前が稼働していること。 ・攻撃者が対象のTeamCityサーバへHTTP(S)アクセス可能であること。 ・認証は不要。 ________________________________________ ✅悪用時影響 ・認証チェックを回避され、限定的な管理者アクションを実行される ・TeamCityサーバの管理権限を取得される ・機密情報の取得、設定情報の改変、サービス影響につながる ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開済み (NVD) ・ITW:確認済み。トレンドマイクロは、CVE-2024-27198およびCVE-2024-27199を悪用しようとする攻撃者活動を確認したと報告。 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2024-27199 https://blog.jetbrains.com/teamcity/2024/03/additional-critical-security-issues-affecting-teamcity-on-premises-cve-2024-27198-and-cve-2024-27199-update-to-2023-11-4-now/ https://www.cisa.gov/news-events/alerts/2026/04/20/cisa-adds-eight-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    The post enumerates several high‑severity CVEs, confirms active exploitation in the wild, references vendor advisories, and indicates the availability of public PoC or exploit information.

    000415.9K
    43.6K followersView on X
  • Vivek | Cybersecurity@VivekIntel
    Active Exploitation

    🚨 10,000+ Zimbra Servers Exposed to Active XSS Attacks → Attack: Unpatched XSS flaw (CVE-2025-48700) triggered via malicious email, no user interaction needed → Impact: Session hijacking + sensitive data theft across gov & enterprise email systems 💡 Insight: Old patches ≠ safe — attackers exploit long-known bugs at scale ⚠️ Action: Patch immediately, disable vulnerable UI, monitor email-based payloads https://www.bleepingcomputer.com/news/security/cisa-says-zimbra-flaw-now-exploited-over-10k-servers-vulnerable/

    Post summary

    CVE-2025-48700 is a client‑side XSS vulnerability in Zimbra that is currently being exploited at scale, affecting more than 10,000 servers, and users are advised to patch immediately and disable the vulnerable UI.

    10012815
    7.6K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Active Exploitation

    Over 10,500 Zimbra servers remain vulnerable to CVE-2025-48700, an XSS flaw exploited by APT28 and APT29 in targeted phishing and mass intrusions. CISA lists it in KEV for federal patching. #ZimbraServer #CrossSiteScripting #USA https://ift.tt/2wUiK1T

    Post summary

    CVE-2025-48700 is an XSS vulnerability actively exploited by APT28 and APT29, with federal agencies prompted to apply patches per CISA KEV.

    10020791
    4.4K followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    🚨 CVE-2025-48700 (Zimbra ZCS): No-interaction XSS → arbitrary JS in any user's mail session → full email account takeover. 10,000+ servers still unpatched. Actively exploited in wild. Patched Jun 2025 — most orgs asleep. Zimbra admins: update NOW. #ZeroDay #Zimbra

    Post summary

    CVE‑2025‑48700 is a no‑interaction XSS that has been actively exploited in the wild, allowing full email account takeover on over 10,000 unpatched Zimbra servers; it was patched in June 2025 but many organizations remain vulnerable.

    100101.1K
    226 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2024-7399 2 - CVE-2023-50224 3 - CVE-2025-48700 4 - CVE-2025-20333 5 - CVE-2026-5281 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post simply lists five CVE identifiers as trending, without providing technical details, PoCs, exploits, or patch information.

    00011811
    1.7K followersView on X
  • The Shadowserver Foundation@Shadowserver
    Patch

    IP data in Vulnerable HTTP reporting: https://www.shadowserver.org/what-we-do/network-reporting/vulnerable-http-report/ See https://wiki.zimbra.com/wiki/Security_Center for patch info. Dashboard World Map view: https://dashboard.shadowserver.org/statistics/combined/map/?date_range=1&map_type=std&source=http_vulnerable&source=http_vulnerable6&tag=cve-2025-48700%2B&data_set=count&scale=log&auto_update=on Dashboard Tree Map view: https://dashboard.shadowserver.org/statistics/combined/tree/?date_range=1&source=http_vulnerable&source=http_vulnerable6&tag=cve-2025-48700%2B&data_set=count&scale=log&auto_update=on CVE-2025-48700 Tracker: https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=7&source=http_vulnerable&source=http_vulnerable6&tag=cve-2025-48700%2B&dataset=unique_ips&limit=100&group_by=geo&stacking=stacked&auto_update=on

    Post summary

    The notice highlights reporting dashboards for CVE‑2025‑48700 and directs readers to patch information, without indicating active exploitation or technical specifics.

    010101.1K
    21.8K followersView on X
  • CCB Alert@CCBalert
    Active Exploitation

    Warning: Cross-site scripting vulnerability in #Zimbra Collaboration Suite. #CVE-2025-48700 CVSS: 6.1. This vulnerability is #actively exploited to access unauthorised information. #Patch #Patch #Patch

    Post summary

    The post warns of a CVE-2025-48700 XSS flaw in Zimbra Collaboration Suite that is actively exploited, with a CVSS of 6.1 and an implied patch being available.

    01000323
    7.2K followersView on X
  • キタきつね@foxbook
    Active Exploitation

    CISAが既知の悪用された脆弱性8件をカタログに追加 CISA Adds Eight Known Exploited Vulnerabilities to Catalog #CISA (Apr 20) CVE-2023-27351 PaperCut NG/MF 認証エラーの脆弱性 CVE-2024-27199 JetBrains TeamCity 相対パストラバーサル脆弱性 CVE-2025-2749 Kentico Xperienceのパストラバーサル脆弱性 CVE-2025-32975 Quest KACEシステム管理アプライアンス(SMA)の認証エラーの脆弱性 CVE-2025-48700 Synacor Zimbra Collaboration Suite (ZCS) のクロスサイトスクリプティング脆弱性 CVE-2026-20122 Cisco Catalyst SD-WAN Managerにおける特権APIの不適切な使用に関する脆弱性 CVE-2026-20128 Cisco Catalyst SD-WAN Managerにおける、パスワードを回復可能な形式で保存する脆弱性 CVE-2026-20133 Cisco Catalyst SD-WAN Managerにおける機密情報が不正アクセス者に漏洩する脆弱性 https://www.cisa.gov/news-events/alerts/2026/04/20/cisa-adds-eight-known-exploited-vulnerabilities-catalog

    Post summary

    CISA has publicly added eight CVEs that are known to have been exploited, though no PoC, exploit code, or patch details are discussed.

    00010559
    4.8K followersView on X
  • kokumօtօ@__kokumoto
    General

    CVE-2023-27351 PaperCut NG/MF CVE-2024-27199 JetBrains TeamCity CVE-2025-2749 Kentico Xperience CVE-2025-32975 Quest KACE Systems Management Appliance (SMA) CVE-2025-48700 Zimbra Collaboration Suite (ZCS) CVE-2026-20122/CVE-2026-20128/CVE-2026-20133 Cisco Catalyst SD-WAN Manager

    Post summary

    The content merely lists several CVE identifiers alongside the affected products, offering no further detail, evidence of exploitation, or mitigation information.

    10000812
    7.4K followersView on X
  • Michael Martino@battista212
    Active Exploitation

    CISA just added 8 vulnerabilities to Known Exploited Catalog. Active exploitation confirmed. CVE-2025-48700 (Zimbra XSS), CVE-2025-32975 (Quest KACE), CVE-2024-27199 (JetBrains TeamCity). If you're running these, you're already compromised. #Cybersecurity #CISA

    Post summary

    CISA confirms active exploitation of eight CVEs, including XSS in Zimbra, indicating that systems running these may already be compromised.

    10000346
    202 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidad en productos Zimbra ❗ CVE-2025-48700 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-zimbra-2/ https://t.co/rM4LjwrFys

    Post summary

    The tweet announces a Zimbra vulnerability (CVE‑2025‑48700) and directs readers to external links for more information, but supplies no additional technical, exploit, or remediation details.

    00000692
    6.7K followersView on X
  • Hephaestvs@Vulcanux_
    Active Exploitation

    csirt_it: La Settimana Cibernetica del 26 aprile 2026 🔹aggiornamenti per molteplici prodotti 🔹Zimbra: rilevato sfruttamento in rete della CVE-2025-48700 🔹Libreria protobufjs: disponibile PoC per lo sfruttamento della CVE 2026-41242 ⚠️#EPSS 🔗 … https://t.co/oZi6IeUUpY

    Post summary

    The tweet reports that CVE‑2025‑48700 is being actively exploited on the network and that a PoC is available for CVE‑2026‑41242.

    00000671
    610 followersView on X
  • SecOpsSam@gbc13
    Active Exploitation

    *Over 10,000 internet-exposed Zimbra servers remain vulnerable while exploitation continues* Why it matters: with CVE-2025-48700 now in KEV, unpatched mail/collaboration servers remain a high-probability initial access path. Source: https://www.bleepingcomputer.com/news/security/cisa-says-zimbra-flaw-now-exploited-over-10k-servers-vulnerable/

    Post summary

    The article reports that CVE‑2025‑48700 is actively exploited against more than 10,000 unmanaged Zimbra servers, underscoring a serious ongoing threat.

    00000697
    126 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploited CVE-2025-48700 XSS vulnerability in 10,000+ unpatched Zimbra servers through crafted emails. Post-compromise lateral movement allowed network-wide pivoting. Runtime segmentation helps contain such breach chains after initial email system compromise. #ZeroTrust 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/zimbra-cve-2025-48700-xss-vulnerability-exploitation-2026

    Post summary

    Attackers leveraged a Zimbra XSS flaw (CVE‑2025‑48700) in over 10,000 unpatched servers via crafted emails, enabling lateral movement and network pivoting.

    00000621
    1.9K followersView on X
  • PurpleOps@PurpleOps_io
    Active Exploitation

    🔥 𝐎𝐯𝐞𝐫 𝟏𝟎,𝟎𝟎𝟎 𝐙𝐢𝐦𝐛𝐫𝐚 𝐬𝐞𝐫𝐯𝐞𝐫𝐬 𝐯𝐮𝐥𝐧𝐞𝐫𝐚𝐛𝐥𝐞 𝐭𝐨 𝐨𝐧𝐠𝐨𝐢𝐧𝐠 𝐗𝐒𝐒 𝐚𝐭𝐭𝐚𝐜𝐤𝐬 • Over 10,000 Zimbra Collaboration Suite (ZCS) instances exposed online are vulnerable to active XSS attacks. • The CVE-2025-48700 flaw affects ZCS versions 8.8.15, 9.0, 10.0, and 10.1, allowing unauthenticated JavaScript execution. • CISA added this Zimbra XSS vulnerability to its Known Exploited Vulnerabilities Catalog due to observed active exploitation. Over 10,000 Zimbra servers remain vulnerable to an actively exploited cross-site scripting flaw, despite patches being available.

    Post summary

    Over 10,000 Zimbra servers are vulnerable to CVE‑2025‑48700 XSS, and the vulnerability is actively exploited in the wild, with patches already available.

    00000552
    99 followersView on X
  • UNDERCODE NEWS@UndercodeNews
    Active Exploitation

    🚨 Over 10,000 Zimbra Servers Exposed to Active XSS Exploits as #CVE-2025-48700 Attacks Spread Globally -Fact Checker: ✅: 4 ❌: 0 || 4/4 http://undercodenews.com/over-10000-zimbra-servers-exposed-to-active-xss-exploits-as-cve-2025-48700-attacks-spread-globally/

    Post summary

    The text reports that more than 10,000 Zimbra servers are being targeted through the #CVE-2025-48700 XSS vulnerability, indicating widespread active exploitation. No information on patches, tools, or technical specifics is provided.

    00000550
    756 followersView on X
  • Nicolas Coolman@NicolasCoolman
    Active Exploitation

    ⚠️Alerte critique sur Zimbra : CVE-2025-48700 activement exploitée (zoneantimalware..com) https://t.co/cQ9nI8sm2f

    Post summary

    The tweet flags that the Zimbra CVE‑2025‑48700 is being actively exploited in the wild.

    00000435
    85 followersView on X
  • CiberPlaneta@CiberPlanetaOrg
    Disclosure

    🛡️ Vulnerabilidad XSS en Zimbra: CVE-2025-48700 Análisis y Mitigaciones Descubre el análisis técnico de la vulnerabilidad CVE-2025-48700 en Synacor Zimbra Collaboration Suite, un XSS que permite ejecución de JavaScript. Impacto, rec https://www.ciberplaneta.org/vulnerabilidades/vulnerabilidad-xss-en-zimbra-cve-2025-48700-analisis-y-mitigaciones/ #ciberplaneta #vulnerabilidades #cve_2025_48700 #cve #vulnerabilidad #synacor #seguridad #infosec #ciberseguridad

    Post summary

    The post provides a technical analysis and mitigation guidance for the XSS vulnerability CVE-2025-48700 in Zimbra, highlighting how JavaScript can be executed and recommending countermeasures.

    00000283
    6 followersView on X
CPE platform detail93 entries

93 of 93 entries

PartVendorProductVersionTarget SWTarget HW
Appsynacorzimbra_collaboration_suite---
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite8.8.15--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--
Appsynacorzimbra_collaboration_suite9.0.0--

Explore more