LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-27915: Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability

RBRecent Breaches Vulnerability Intelligence·Oct 7, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Oct 28, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-27915 to its Known Exploited Vulnerabilities catalog on Oct 7, 2025, with a federal patch deadline of Oct 28, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that exists in the Classic Web Client due to insufficient sanitization of HTML content in ICS files. When a user…

CVE-2025-27915 is a cross-site scripting vulnerability in Synacor Zimbra Collaboration Suite (ZCS). It affects the Classic Web Client and stems from insufficient sanitization of HTML content inside ICS files. When a user opens an email that contains a crafted ICS entry, attacker-controlled JavaScript can run in the victim’s authenticated session. That access can let an attacker perform unauthorized account actions such as creating mail filters that redirect messages, which in turn enables data exfiltration. Organizations that run Zimbra for email and calendaring should treat this as a high-priority issue for any users of the Classic Web Client.

How it works

The weakness is classified as CWE-79 (cross-site scripting). According to the CISA summary, the Classic Web Client fails to properly sanitize HTML content carried in ICS calendar attachments. An attacker embeds malicious markup that includes an ontoggle event handler inside a tag. When the recipient views the message, the browser executes the embedded JavaScript in the context of the logged-in Zimbra session. Because the script runs with the victim’s privileges, it can issue requests that the user is authorized to make—most notably the creation or modification of email filters that silently forward mail to an attacker-controlled address. The same capability can be used for other unauthorized actions or for harvesting data visible to the session. Exact payload construction and any additional vectors must be confirmed against the vendor advisory; no further exploit mechanics are provided in the public summary.

Am I affected? How to find it in your systems

Zimbra Collaboration Suite is commonly deployed as an on-premises or hosted email, calendar, and collaboration platform. The vulnerability is specific to the Classic Web Client interface. Inventory steps include:

Telemetry that shows unexpected JavaScript errors or unusual session activity after ICS rendering can also serve as an indicator, but absence of such signals does not prove the environment is clean.

How to remediate

Apply the vendor-supplied update or mitigation instructions for CVE-2025-27915 as soon as they are available. CISA’s required action is to follow the vendor’s guidance, apply applicable BOD 22-01 controls for any cloud-hosted instances, or discontinue use of the product if mitigations cannot be obtained. After patching:

Document the change window and retain evidence of the applied fix for compliance and incident-response purposes.

If you can't patch immediately

Until the vendor update can be installed, reduce exposure with the following compensating controls:

These measures lower risk but do not eliminate the underlying flaw; schedule the official patch without delay.

If your data may have been exposed

Actively exploited vulnerabilities of this type can lead to account takeover and subsequent data breaches through mail redirection or session abuse. If you suspect compromise, immediately revoke active sessions, reset credentials for affected users, and examine mail filters and forwarding rules for unauthorized changes. You can also run a free exposure scan of your email address against known breach data to determine whether credentials or personal information have already appeared in public breach corpora.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSynacor · Zimbra Collaboration Suite (ZCS)
WeaknessCWE-79
Added to CISA KEVOct 7, 2025
Federal patch deadlineOct 28, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities