LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-37042: Synacor Zimbra Collaboration Suite (ZCS) Authentication Bypass Vulnerability

RBRecent Breaches Vulnerability Intelligence·Aug 11, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Sep 1, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-37042 to its Known Exploited Vulnerabilities catalog on Aug 11, 2022, with a federal patch deadline of Sep 1, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Synacor Zimbra Collaboration Suite (ZCS) contains an authentication bypass vulnerability in MailboxImportServlet. This vulnerability was chained with CVE-2022-27925 which allows for unauthenticated…

CVE-2022-37042 is an authentication bypass vulnerability in Synacor Zimbra Collaboration Suite (ZCS), specifically in the MailboxImportServlet component. It matters because attackers can bypass authentication controls and, when chained with CVE-2022-27925, achieve unauthenticated remote code execution on affected Zimbra servers. This combination has been used in ransomware activity, putting email systems, mailboxes, and connected infrastructure at direct risk.

IT and security teams running Zimbra should treat this as a high-priority exposure: the product is commonly internet-facing for webmail and collaboration, so successful abuse can lead to full server compromise, data theft, and follow-on ransomware. Confirm all version and patch details against the vendor advisory before acting.

How it works

The weakness is classified as CWE-23 (relative path traversal). In this case it manifests as an authentication bypass in MailboxImportServlet. An unauthenticated attacker can abuse the flawed handling of requests to that servlet to gain unauthorized access without valid credentials.

Public reporting indicates the bypass was chained with a separate vulnerability (CVE-2022-27925) to reach unauthenticated remote code execution. Exact request construction and payload details are not repeated here; defenders should obtain mechanics and indicators solely from the vendor advisory and trusted threat-intelligence sources. The practical outcome is that an external attacker who can reach the vulnerable servlet may escalate from no authentication to code execution on the Zimbra host.

Am I affected? How to find it in your systems

Zimbra Collaboration Suite typically runs on Linux servers providing webmail, calendar, and related services, often exposed on HTTPS (ports 443/8443) and sometimes additional admin or proxy ports. Inventory every host that presents Zimbra web interfaces, mailbox services, or the MailboxImportServlet endpoint.

If you cannot confirm the exact patch level, assume the instance is vulnerable until verified against the vendor’s guidance.

How to remediate

Patch first. Apply the updates published by Synacor for Zimbra Collaboration Suite exactly as described in the vendor advisory and follow CISA’s required action: apply updates per vendor instructions. Schedule the maintenance window promptly, take configuration and mailbox backups beforehand, and verify service health after the upgrade.

If you can't patch immediately

Implement compensating controls to reduce exposure until the vendor update can be applied.

These measures lower risk but do not replace the vendor patch; schedule the official update as soon as practicable.

If your data may have been exposed

Actively exploited vulnerabilities that enable remote code execution, especially those with known ransomware use, frequently precede data theft and extortion. If your Zimbra environment was reachable and unpatched during the period of exploitation, assume possible mailbox and credential exposure. Preserve logs and disk images for incident response, reset affected credentials, and follow your organization’s breach-notification procedures. You can run a free exposure scan of your email addresses against known breach data sets to check whether associated accounts already appear in public dumps, then prioritize monitoring and password changes accordingly.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSynacor · Zimbra Collaboration Suite (ZCS)
WeaknessCWE-23
Added to CISA KEVAug 11, 2022
Federal patch deadlineSep 1, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities