LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-7796: Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 17, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 10, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-7796 to its Known Exploited Vulnerabilities catalog on Feb 17, 2026, with a federal patch deadline of Mar 10, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Synacor Zimbra Collaboration Suite (ZCS) contains a server-side request forgery vulnerability if WebEx zimlet installed and zimlet JSP is enabled.

This vulnerability is a server-side request forgery issue in Synacor Zimbra Collaboration Suite. It is present only when the WebEx zimlet is installed and zimlet JSP is enabled. The flaw matters because it can let an attacker cause the server to issue requests to internal systems or external resources that should remain inaccessible from outside.

How it works

The weakness is classified as CWE-918, server-side request forgery. In this class of flaw an attacker supplies input that the application uses when making its own outbound requests. The server then performs those requests on the attacker's behalf, which can expose internal services, bypass network boundaries, or retrieve data the attacker could not reach directly.

Am I affected? How to find it in your systems

Zimbra Collaboration Suite runs as an on-premises email and groupware server. Begin by locating every installation through asset inventories, configuration management databases, or network scans for Zimbra services. For each instance determine whether the WebEx zimlet is present and whether zimlet JSP execution is enabled. Exact version numbers and configuration flags must be confirmed against the vendor advisory.

How to remediate

Apply the vendor-supplied update or configuration change listed in the official advisory. After patching, review all enabled zimlets and disable any that are not required. Disable zimlet JSP execution if it is not needed for business functions. Follow applicable BOD 22-01 guidance for any cloud-hosted instances.

If you can't patch immediately

Apply mitigations exactly as described in the vendor instructions. Where mitigations cannot be implemented, discontinue use of the affected product. Segment the Zimbra servers so they cannot reach internal resources that should not be accessible from the application tier. Monitor outbound traffic from the servers for anomalies until remediation is complete.

If your data may have been exposed

Vulnerabilities in this class have been leveraged in data breaches. Organizations can run a free exposure scan of their domains to check for presence in known breach data sets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSynacor · Zimbra Collaboration Suite
WeaknessCWE-918
Added to CISA KEVFeb 17, 2026
Federal patch deadlineMar 10, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities