LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-24682: Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 25, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Mar 11, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-24682 to its Known Exploited Vulnerabilities catalog on Feb 25, 2022, with a federal patch deadline of Mar 11, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (XSS) vulnerability in the Calendar feature that allows an attacker to execute arbitrary code.

CVE-2022-24682 is a cross-site scripting vulnerability in the Calendar feature of Synacor Zimbra Collaboration Suite (ZCS). It allows an attacker to execute arbitrary code in the context of a victim’s session. Because Zimbra is widely used for enterprise email and calendaring, successful abuse can lead to account takeover, data theft, and further lateral movement. CISA notes known ransomware use of this vulnerability, so organizations running ZCS should treat it as a priority.

Public detail is limited to the Calendar component and the stated weakness classes; exact affected builds, attack prerequisites, and scoring must be confirmed against the vendor advisory.

How it works

The flaw is classified under CWE-79 (Improper Neutralization of Input During Web Page Generation) and CWE-116 (Improper Encoding or Escaping of Output). In essence, user-controlled or attacker-supplied content that reaches the Calendar feature is not properly sanitized or encoded before being rendered in a victim’s browser.

An attacker who can introduce malicious script into Calendar data—through an invitation, shared event, or other Calendar input path—can cause that script to execute when a legitimate user views the item. Because the script runs with the privileges of the authenticated Zimbra session, the attacker can perform actions as the victim, steal session tokens, or pivot to other parts of the collaboration suite. No further exploit mechanics are provided in the public summary; defenders should treat any untrusted Calendar content as a potential vector until the vendor patch is applied.

Am I affected? How to find it in your systems

Zimbra Collaboration Suite typically runs as an on-premises or self-hosted mail and calendaring platform, often exposed to the internet for webmail and mobile access. Inventory every server or virtual machine that hosts ZCS, including any secondary or lab instances.

Any system still running an unpatched build that includes the vulnerable Calendar code should be considered exposed until verified otherwise.

How to remediate

The primary remediation is to apply the updates supplied by Synacor/Zimbra exactly as described in the vendor advisory. CISA’s required action is simply “Apply updates per vendor instructions.”

If you can't patch immediately

When immediate patching is not feasible, apply compensating controls to reduce the attack surface until the update can be installed.

If your data may have been exposed

Actively exploited vulnerabilities, especially those with documented ransomware use, frequently precede broader compromise. If you have evidence of exploitation or cannot rule it out, assume credentials and mailbox data may have been accessed. Rotate passwords and app tokens for affected accounts, review mail-forwarding rules and delegation settings, and examine backups for integrity before restoration. You can also run a free exposure scan of your email addresses against known breach data to determine whether those addresses already appear in public breach corpora.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSynacor · Zimbra Collaborate Suite (ZCS)
WeaknessCWE-79
Added to CISA KEVFeb 25, 2022
Federal patch deadlineMar 11, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities