<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — Synacor</title><description>Actively exploited vulnerabilities affecting Synacor products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/synacor.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-73570 — Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-73570</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-73570</guid><description>This vulnerability in Zimbra Collaboration Suite allows an unauthenticated attacker to inject and execute arbitrary operating system commands simply by sending crafted SMTP requests — no login required. Because Zimbra is widely used for enterprise email, a successful exploit could give attackers a foothold on the mail server running as the Zimbra user, potentially enabling data theft, lateral movement, or further compromise of the organization&apos;s messaging infrastructure.</description><pubDate>Fri, 21 Aug 2026 00:00:00 GMT</pubDate><category>Synacor</category><category>Zimbra Collaboration Suite (ZCS)</category></item><item><title>CVE-2025-48700 — Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-48700</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-48700</guid><description>This cross-site scripting (XSS) flaw in Zimbra Collaboration Suite lets attackers inject and run malicious JavaScript inside a victim&apos;s active session. Because Zimbra is a widely used enterprise email and collaboration platform, successful exploitation could allow attackers to steal session tokens, credentials, or other sensitive data without the user&apos;s knowledge. Organizations relying on Zimbra for internal or external communication face real risk of account compromise and data exposure.</description><pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate><category>Synacor</category><category>Zimbra Collaboration Suite (ZCS)</category></item><item><title>CVE-2025-66376 — Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-66376</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-66376</guid><description>This vulnerability in Zimbra Collaboration Suite&apos;s Classic UI allows attackers to inject malicious scripts via CSS @import directives embedded in HTML emails. When a user views a crafted email, the attacker&apos;s code can execute in the victim&apos;s browser session, potentially enabling session hijacking, credential theft, or further attacks against the user&apos;s Zimbra account. Because email is a universal attack surface, any organization running ZCS Classic UI is exposed to phishing-style exploitation without requiring any special user action beyond opening a message.</description><pubDate>Wed, 18 Mar 2026 00:00:00 GMT</pubDate><category>Synacor</category><category>Zimbra Collaboration Suite (ZCS)</category></item><item><title>CVE-2020-7796 — Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability</title><link>https://wildfortech.com/security#CVE-2020-7796</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2020-7796</guid><description>This vulnerability in Zimbra Collaboration Suite allows an attacker to perform server-side request forgery (SSRF) when the WebEx zimlet is installed and its JSP component is enabled. SSRF lets attackers trick the server into making unauthorized requests to internal or external resources, potentially exposing internal services, bypassing network controls, or facilitating further attacks. Organizations running affected ZCS deployments with the WebEx zimlet active are at direct risk.</description><pubDate>Tue, 17 Feb 2026 00:00:00 GMT</pubDate><category>Synacor</category><category>Zimbra Collaboration Suite</category></item><item><title>CVE-2025-68645 — Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-68645</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-68645</guid><description>This vulnerability in Zimbra Collaboration Suite lets remote attackers manipulate how the server processes requests to its /h/rest endpoint, tricking it into including arbitrary files from the WebRoot directory. Because no authentication barrier is implied as a prerequisite, attackers could potentially read sensitive files or execute malicious code, threatening the confidentiality and integrity of a widely-used enterprise email and collaboration platform.</description><pubDate>Thu, 22 Jan 2026 00:00:00 GMT</pubDate><category>Synacor</category><category> Zimbra Collaboration Suite (ZCS)</category></item><item><title>CVE-2025-27915 — Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-27915</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-27915</guid><description>This vulnerability allows an attacker to embed malicious JavaScript inside a calendar invitation (ICS file) sent via email. When a Zimbra Classic Web Client user opens or previews the message, the script executes automatically within their authenticated session. The attacker can then perform actions as the victim, including creating email filters that silently redirect incoming messages to an attacker-controlled address — enabling ongoing data theft without the victim&apos;s knowledge.</description><pubDate>Tue, 07 Oct 2025 00:00:00 GMT</pubDate><category>Synacor</category><category>Zimbra Collaboration Suite (ZCS)</category></item><item><title>CVE-2019-9621 — Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) Vulnerability</title><link>https://wildfortech.com/security#CVE-2019-9621</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2019-9621</guid><description>This vulnerability in Zimbra Collaboration Suite&apos;s ProxyServlet component allows an attacker to forge server-side requests, meaning the Zimbra server can be manipulated into making HTTP requests on an attacker&apos;s behalf. This can expose internal network resources, bypass access controls, or allow attackers to pivot deeper into an organization&apos;s infrastructure — particularly dangerous given how widely ZCS is used as enterprise email and collaboration infrastructure.</description><pubDate>Mon, 07 Jul 2025 00:00:00 GMT</pubDate><category>Synacor</category><category>Zimbra Collaboration Suite (ZCS)</category></item><item><title>CVE-2024-27443 — Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability</title><link>https://wildfortech.com/security#CVE-2024-27443</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2024-27443</guid><description>This vulnerability in Zimbra&apos;s classic webmail interface allows attackers to execute arbitrary JavaScript in a victim&apos;s browser simply by sending a specially crafted calendar invite email. No user interaction beyond viewing the message is implied — the malicious code runs automatically via a manipulated calendar header. For organizations running Zimbra, this means an attacker could potentially hijack user sessions, steal credentials, or perform actions on behalf of the victim within the webmail application.</description><pubDate>Mon, 19 May 2025 00:00:00 GMT</pubDate><category>Synacor</category><category>Zimbra Collaboration Suite (ZCS)</category></item></channel></rss>