๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2025-48700: Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability
Summary
Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability (XSS, a flaw where attackers inject malicious code that runs in a user's browser). An attacker could use this to execute arbitrary JavaScript within a user's session, potentially stealing sensitive information or gaining unauthorized access.
Solution / Mitigation
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. See vendor security advisories at https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories for specific patches and updates.
Vulnerability Details
EPSS: 0.2%
Yes
๐ฅ Actively Exploited
April 19, 2026
Classification
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-48700
First tracked: April 20, 2026 at 08:00 PM
Classified by LLM (prompt v3) ยท confidence: 95%