LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-48700: Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 20, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 23, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-48700 to its Known Exploited Vulnerabilities catalog on Apr 20, 2026, with a federal patch deadline of Apr 23, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that could allow attackers to execute arbitrary JavaScript within the user's session, potentially leading to…

Synacor Zimbra Collaboration Suite contains a cross-site scripting vulnerability tracked as CVE-2025-48700. The flaw falls under CWE-79 and can allow an attacker to execute arbitrary JavaScript inside an authenticated user's browser session, which may expose session tokens or other sensitive data visible to that user.

How it works

CWE-79 describes improper neutralization of input during web page generation. In this class of weakness an attacker supplies data that the application later renders without adequate escaping, so the browser interprets the data as executable script rather than plain text.

Am I affected? How to find it in your systems

Synacor Zimbra Collaboration Suite is an on-premises or hosted email and groupware platform. Inventory all internet-facing and internal instances by checking DNS records, load-balancer configurations, and server inventories for Zimbra services.

How to remediate

Apply the vendor-supplied update referenced in the official advisory. After patching, review the application's handling of user-supplied content and ensure standard output-encoding practices are in place for all rendered fields.

If you can't patch immediately

Until the update can be applied, reduce exposure through network and application controls.

If your data may have been exposed

Cross-site scripting flaws that are actively exploited can result in account compromise and subsequent data exposure. Organizations can run a free exposure scan of their email addresses against known breach datasets to check for signs of prior credential leakage.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSynacor · Zimbra Collaboration Suite (ZCS)
WeaknessCWE-79
Added to CISA KEVApr 20, 2026
Federal patch deadlineApr 23, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities