LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-68645: Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jan 22, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Feb 12, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-68645 to its Known Exploited Vulnerabilities catalog on Jan 22, 2026, with a federal patch deadline of Feb 12, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Synacor Zimbra Collaboration Suite (ZCS) contains a PHP remote file inclusion vulnerability that could allow for remote attackers to craft requests to the /h/rest endpoint to influence internal…

Synacor Zimbra Collaboration Suite contains a PHP remote file inclusion vulnerability. Attackers can craft requests that cause the application to include arbitrary files from its WebRoot directory, potentially leading to unauthorized access within the collaboration environment. This matters for organizations that rely on ZCS for email and shared services, as the flaw affects request handling at a core endpoint.

How it works

The weakness is categorized as CWE-98. It allows remote attackers to influence internal request dispatching by sending crafted requests to the /h/rest endpoint.

Am I affected? How to find it in your systems

Zimbra Collaboration Suite typically runs as an on-premises or hosted email and groupware server. Inventory deployments by locating ZCS installations and their web application components.

How to remediate

Apply the vendor update referenced in the official advisory. After patching, review PHP file-handling settings and restrict unnecessary inclusion of files from the WebRoot directory.

If you can't patch immediately

Apply mitigations per the vendor instructions. Segment networks so that only authorized systems can reach the ZCS web endpoints.

If your data may have been exposed

Actively exploited vulnerabilities in this class can result in breaches. Run a free exposure scan of organizational email addresses against known breach data to identify potential prior exposure.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSynacor · Zimbra Collaboration Suite (ZCS)
WeaknessCWE-98
Added to CISA KEVJan 22, 2026
Federal patch deadlineFeb 12, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities