CVE-2025-68645Active Exploitation(synacor / zimbra_collaboration_suite)

HIGHCVSS 8.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch synacor zimbra_collaboration_suite systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper handling of user-supplied request parameters in the RestFilter servlet. An unauthenticated remote attacker can craft requests to the /h/rest endpoint to influence internal request dispatching, allowing inclusion of arbitrary files from the WebRoot directory.

7.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-02-12. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Vendor / third-party advisories
Weakness type (CWE)
CWE-98

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • zimbra_collaboration_suite

Threat summary

  • Active exploitation appears in 5 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 7 mentions across 7 observed days

What's happening

  • Active exploitation reported across 5 signals
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Peaked 6d ago at 1 mentions (2026-01-29); latest day: 1
  • 7 total mentions across 7 days

Affected systems

Vendors
Products
zimbra_collaboration_suite

Deep dive

Activity timeline7 mentions / 7d
00111Mentions · 2026-01-29: 1Mentions · 2026-01-30: 1Mentions · 2026-01-31: 1Mentions · 2026-02-02: 1Mentions · 2026-02-06: 1Mentions · 2026-02-25: 1Mentions · 2026-02-26: 1PoC Mentioned / Linked · 2026-01-30: 1Exploit Tool / Code · 2026-01-30: 1Exploit Tool / Code · 2026-02-25: 1Active Exploitation · 2026-01-29: 1Active Exploitation · 2026-01-30: 1Active Exploitation · 2026-02-02: 1Active Exploitation · 2026-02-25: 1Active Exploitation · 2026-02-26: 1Patch / Workaround · 2026-01-30: 1Patch / Workaround · 2026-01-31: 1Patch / Workaround · 2026-02-06: 1Technical Details · 2026-01-30: 1Technical Details · 2026-01-31: 1Technical Details · 2026-02-02: 1Technical Details · 2026-02-25: 1Technical Details · 2026-02-26: 101-2901-3001-3102-0202-0602-2502-26
Signal classification2 categories
Active Exploitation
571.4%
Patch
228.6%
Referenced assets30 URLs
Classification over time
DateTotalLabels
2026-01-291
Active Exploitation1
2026-01-301
Active Exploitation1
2026-01-311
Patch1
2026-02-021
Active Exploitation1
2026-02-061
Patch1
2026-02-251
Active Exploitation1
2026-02-261
Active Exploitation1
Full discourse7 posts
  • FortiGuard Labs@FortiGuardLabs
    Active Exploitation

    🔔 New Outbreak Alert: #FortiGuardLabs confirmed an actively exploited Local File Inclusion (LFI) vulnerability in #Zimbra Collaboration Suite Webmail Classic UI (CVE-2025-68645) allowing unauthenticated attackers to expose sensitive configuration files and application data. Get full details: https://ftnt.net/6013hs78P 👈

    Post summary

    FortiGuardLabs reports that CVE-2025-68645, a local file inclusion vulnerability in Zimbra Collaboration Suite Webmail Classic UI, is actively exploited, allowing unauthenticated attackers to read sensitive configuration files and application data.

    01041543
    40.9K followersView on X
  • CrowdSec@Crowd_Security
    Active Exploitation

    🚨 This week’s CrowdSec Threat Alert article highlights CVE-2025-68645 (LFI) and CVE-2022-27926 (XSS), actively exploited in the wild against Zimbra Collaboration servers. Explore attack details, threat trends, and mitigation steps in the article 👉 https://www.crowdsec.net/vulntracking-report/zimbra-collaboration-coordinated-attack #CVE #CVE202568645 #CVE202227926 #threatalert #cybersecurity

    Post summary

    The article reports that CVE-2025-68645 (LFI) and CVE-2022-27926 (XSS) have been actively exploited in the wild against Zimbra Collaboration servers, with mitigation steps discussed in the linked CrowdSec Threat Alert.

    01020312
    19.6K followersView on X
  • 0x0fff@ox0ffff
    Patch

    CISA has confirmed that a critical vulnerability in Synacor Zimbra Collaboration Suite (ZCS) poses significant risks to organizations worldwide. This PHP remote file inclusion flaw, tracked as CVE-2025-68645, allows attackers to manipulate the /h/rest endpoint to include arbitrary files from the WebRoot directory. While the vulnerability itself is technical, its implications are deeply intertwined with the global rise in state-sponsored cyber operations and the weaponization of collaboration tools during geopolitical tensions. Nation-state actors and advanced persistent threat groups have increasingly targeted email and communication platforms to intercept sensitive data, disrupt operations, or gain long-term access to critical infrastructure. The Zimbra platform, widely used by SMEs and government agencies, becomes a strategic asset for adversaries seeking to exploit divisions in global supply chains or capitalize on political instability. The market impact of this vulnerability is multifaceted. SMEs relying on ZCS face immediate risks to business continuity, as unpatched systems could lead to data exfiltration, ransomware deployment, or reputational damage. Supply chain dependencies on third-party vendors for updates or support may delay remediation, particularly for organizations in regions with restricted access to cybersecurity resources. Insurance providers are likely to scrutinize incident response plans more rigorously, potentially increasing premiums for businesses that fail to demonstrate proactive patch management. Regulatory compliance also comes into play, as data protection laws such as GDPR or CCPA impose strict requirements for securing customer information. For SMEs operating in volatile markets, the financial and operational costs of a breach could be catastrophic, further straining resources amid inflationary pressures and geopolitical trade barriers. From a technical perspective, CVE-2025-68645 exploits a flaw in how ZCS handles file inclusion requests, enabling attackers to execute arbitrary code or access sensitive files. This vulnerability is particularly dangerous because it requires minimal user interaction and can be triggered remotely, bypassing traditional network defenses. Threat actors could leverage this to deploy malware, establish persistent backdoors, or steal credentials, creating a foothold for broader network infiltration. Given the global nature of cyber threats, SMEs must recognize that even locally hosted solutions are not immune to cross-border attacks, especially as adversarial nations invest heavily in cyber capabilities to undermine economic competitors. To mitigate this risk, SMEs should prioritize applying the latest security patches provided by Synacor/Zimbra. For organizations unable to update immediately, implementing strict input validation rules for the /h/rest endpoint and restricting access to trusted IP ranges can reduce exposure. Network segmentation and monitoring for unusual file access patterns will also help detect exploitation attempts. Cybersecurity teams should integrate this vulnerability into their threat modeling frameworks, considering how geopolitical shifts might influence the likelihood of targeted attacks. https://wiki.zimbra.com/wiki/Security_Center ; https://nvd.nist.gov/vuln/detail/CVE-2025-68645 #CVE202568645 #Vulnerability #Patch #OTSecurity #Cybersecurity

    Post summary

    The post discloses a PHP remote file inclusion vulnerability (CVE‑2025‑68645) in Zimbra and stresses applying vendor patches, with mitigation steps for unpatched systems.

    00010121
    453 followersView on X
  • RST Cloud@rst_cloud
    Active Exploitation

    #threatreport #MediumCompleteness January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office Zero-Day | 24-02-2026 Source: https://www.recordedfuture.com/blog/january-2026-cve-landscape Key details below ↓ 🧑‍💻Actors/Campaigns: Fancy_bear Neusploit 💀Threats: Nuclei_tool, Minidoor, Pixynetloader, Covenant_c2_tool, Grunt, Com_hijacking_technique, Supply_chain_technique, 🎯Victims: Enterprise communication platforms, Enterprise management platforms, Government users, Business users, Wordpress sites, Email systems 🏭Industry: Government 🌐Geo: Russian 🔓CVEs: CVE-2026-23760 \[[Vulners](https://vulners.com/cve/CVE-2026-23760)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - smartertools smartermail (<100.0.9511) CVE-2025-34026 \[[Vulners](https://vulners.com/cve/CVE-2025-34026)] - CVSS V3.1: *7.5*, - Vulners: Exploitation: True Soft: - versa-networks concerto (<12.1.2, 12.2.0) CVE-2009-0556 \[[Vulners](https://vulners.com/cve/CVE-2009-0556)] - CVSS V3.1: *8.8*, - Vulners: Exploitation: True Soft: - microsoft office_powerpoint (2004) - microsoft powerpoint (2000, 2002, 2003) CVE-2025-8110 \[[Vulners](https://vulners.com/cve/CVE-2025-8110)] - CVSS V3.1: *8.8*, - Vulners: Exploitation: True Soft: - gogs (le0.13.3) CVE-2026-24423 \[[Vulners](https://vulners.com/cve/CVE-2026-24423)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - smartertools smartermail (<100.0.9511) CVE-2025-68645 \[[Vulners](https://vulners.com/cve/CVE-2025-68645)] - CVSS V3.1: *8.8*, - Vulners: Exploitation: True Soft: - synacor zimbra_collaboration_suite (<10.0.18, <10.1.13) CVE-2018-14634 \[[Vulners](https://vulners.com/cve/CVE-2018-14634)] - CVSS V3.1: *7.8*, - Vulners: Exploitation: True Soft: - paloaltonetworks pan-os (<7.1.23, <8.0.16, <8.1.7) CVE-2026-21509 \[[Vulners](https://vulners.com/cve/CVE-2026-21509)] - CVSS V3.1: *7.8*, - Vulners: Exploitation: True Soft: - microsoft 365_apps (-) - microsoft office (2016, 2019) - microsoft office_long_term_servicing_channel (2021, 2024) CVE-2025-37164 \[[Vulners](https://vulners.com/cve/CVE-2025-37164)] - CVSS V3.1: *10.0*, - Vulners: Exploitation: True Soft: - hpe oneview (le10.20.00) CVE-2026-1340 \[[Vulners](https://vulners.com/cve/CVE-2026-1340)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - ivanti endpoint_manager_mobile (le12.7.0.0) CVE-2026-1281 \[[Vulners](https://vulners.com/cve/CVE-2026-1281)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - ivanti endpoint_manager_mobile (le12.5.0.0, 12.5.1.0, 12.6.0.0, 12.6.1.0, 12.7.0.0) CVE-2026-20045 \[[Vulners](https://vulners.com/cve/CVE-2026-20045)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - cisco unified_communications_manager (<14su5, le15su3a) - cisco unified_communications_manager_im_and_presence_service (<14su5, le15su3a) - cisco unity_connection (<14su5, le15su3) CVE-2026-20931 \[[Vulners](https://vulners.com/cve/CVE-2026-20931)] - CVSS V3.1: *8.0*, - Vulners: Exploitation: Unknown Soft: - microsoft windows_10_1607 (<10.0.14393.8783) - microsoft windows_10_1809 (<10.0.17763.8276) - microsoft windows_10_21h2 (<10.0.19044.6809) - microsoft windows_10_22h2 (<10.0.19045.6809) ... CVE-2026-20805 \[[Vulners](https://vulners.com/cve/CVE-2026-20805)] - CVSS V3.1: *5.5*, - Vulners: Exploitation: True Soft: - microsoft windows_10_1607 (<10.0.14393.8783) - microsoft windows_10_1809 (<10.0.17763.8276) - microsoft windows_10_21h2 (<10.0.19044.6809) - microsoft windows_10_22h2 (<10.0.19045.6809) ... CVE-2025-52691 \[[Vulners](https://vulners.com/cve/CVE-2025-52691)] - CVSS V3.1: *10.0*, - Vulners: Exploitation: True Soft: - smartertools smartermail (<100.0.9413) CVE-2025-31125 \[[Vulners](https://vulners.com/cve/CVE-2025-31125)] - CVSS V3.1: *7.5*, - Vulners: Exploitation: True Soft: - vitejs vite (<4.5.11, <5.4.16, <6.0.13, <6.1.3, <6.2.4) CVE-2026-24858 \[[Vulners](https://vulners.com/cve/CVE-2026-24858)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - fortinet fortianalyzer (le7.0.15, le7.2.11, <7.4.10, <7.6.6) - fortinet fortimanager (le7.0.15, le7.2.11, <7.4.10, <7.6.6) - fortinet fortiproxy (le7.0.22, le7.2.15, le7.4.12, le7.6.4) - fortinet fortiweb (le7.4.11, le7.6.6, le8.0.3) ... CVE-2025-54313 \[[Vulners](https://vulners.com/cve/CVE-2025-54313)] - CVSS V3.1: *7.5*, - Vulners: Exploitation: True Soft: - prettier eslint-config-prettier (8.10.1, 9.1.1, 10.1.6, 10.1.7) CVE-2025-40551 \[[Vulners](https://vulners.com/cve/CVE-2025-40551)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - solarwinds web_help_desk (<2026.1) CVE-2026-20029 \[[Vulners](https://vulners.com/cve/CVE-2026-20029)] - CVSS V3.1: *4.9*, - Vulners: Exploitation: Unknown CVE-2026-23550 \[[Vulners](https://vulners.com/cve/CVE-2026-23550)] - CVSS V3.1: *10.0*, - Vulners: Exploitation: Unknown CVE-2026-23800 \[[Vulners](https://vulners.com/cve/CVE-2026-23800)] - CVSS V3.1: *10.0*, - Vulners: Exploitation: Unknown CVE-2024-37079 \[[Vulners](https://vulners.com/cve/CVE-2024-37079)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - vmware cloud_foundation (<5.2) CVE-2026-24061 \[[Vulners](https://vulners.com/cve/CVE-2026-24061)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - gnu inetutils (le2.7) 🤖LLM extracted TTPs:` T1005, T1027, T1053.005, T1071.001, T1078, T1090, T1098, T1112, T1114.003, T1133, ... 🧨IOCs: - Path: 2 - Registry: 1 - IP: 6 - Email: 4 - File: 2 💽Software: Microsoft Office, Ivanti, Linux, Zimbra Collaboration Suite, WordPress, Outlook, Ivanti EPMM 🔢Algorithms: xor 📜Programming Languages: php #threatreport: In January 2026, there was a noted 5% increase in critical vulnerabilities, with 23 high-impact issues identified. Among these, the exploitation of a significant Microsoft Office zero-day vulnerability (CVE-2026-21509) by Russian state-sponsored group APT28 highlighted ongoing threats to enterprise technologies. This vulnerability, which relates to the reliance on untrusted inputs in security decisions, enabled APT28 to utilize weaponized Rich Text Format (RTF) files to deliver various malicious implants, including MiniDoor, PixyNetLoader, and Covenant Grunt. The exploitation chain initiated with an RTF file that bypassed Office OLE mitigations. The attackers deployed MiniDoor as an Outlook VBA script for email collection, while PixyNetLoader, which created a mutex for persistence, allowed further attacks. A notable aspect of this operation was the use of geography-based evasion to limit the delivery of the malicious payloads, demonstrating the sophistication of the APT28 attacks. In addition to Microsoft, other vendors such as SmarterTools and Ivanti were significantly affected, with SmarterTools reporting multiple critical vulnerabilities allowing authentication bypass and remote code execution (RCE). Specifically, CVE-2026-23760 identified a privilege escalation flaw in SmarterMail, permitting unauthenticated users to reset passwords, demonstrating serious flaws in expected security protocols. Furthermore, the Modular DS WordPress plugin was found to have multiple vulnerabilities, CVE-2026-23550 and CVE-2026-23800, that allowed attackers to gain administrator access without authentication. These vulnerabilities emphasize the risk of widespread exploitation due to the centralized management of multiple WordPress sites.

    Post summary

    The report highlights active exploitation of CVE-2026-21509 by APT28 using weaponized RTF files, along with additional vulnerabilities in SmarterMail and WordPress, underscoring ongoing threats to enterprise systems.

    0000074
    589 followersView on X
  • Miguel Vera@mveracf
    Patch

    🛡️ Heads up! Cloudflare WAF is adding new protections against Zimbra &amp; Vite vulnerabilities (CVE-2025-68645 &amp; CVE-2025-31125) on Feb 9th. Stay secure with our proactive threat detection! 🚀 https://developers.cloudflare.com/changelog/scheduled-waf-release/

    Post summary

    Cloudflare WAF is deploying new protection rules for CVE‑2025‑68645 and CVE‑2025‑31125, indicating a mitigation is available, though technical details are lacking.

    0000071
    1 followersView on X
  • RagingCISO@CisoRaging77913
    Active Exploitation

    CVE-2025-68645: Zimbra LFI—unauth file read via /h/rest. Five-line exploit. Patch available since Nov 2025, exploitation active since Jan 14. Attackers pulling /etc/passwd and OAuth tokens. You sat on the patch for 2 months. Now you're hosting their mail server.

    Post summary

    CVE-2025-68645 is a Zimbra LFI that enables unauthenticated file reads via /h/rest, with a simple five‑line exploit; the vulnerability has been actively exploited since Jan 14, and a patch has been available since Nov 2025.

    0000090
    4 followersView on X
  • Divert@Divert_Security
    Active Exploitation

    @Zimbra Collaboration Suite LFI CVE-2025-68645: Publicly disclosed 12/22/25, detected and blocked for our customers on 1/13/25, and added to #KEV by #CISA on 1/22/26. These particular attempts were sourced from DigitalOcean https://t.co/6HNUT93lex

    Post summary

    The tweet reports that CVE-2025-68645, a Local File Inclusion flaw in Zimbra Collaboration Suite, was publicly disclosed, actively exploited (detected and blocked), and added to the KEV with attacks originating from DigitalOcean.

    0000077
    10 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsynacorzimbra_collaboration_suite---

Explore more