Actively Exploited — CISA KEV
CVE-2024-27443: Synacor Zimbra Collaboration Suite (ZCS) Vulnerability
Severity: Unknown | CVSS 3.1: N/A | KEV Added: 2025-05-19
What is CVE-2024-27443?
Zimbra Collaboration contains a cross-site scripting (XSS) vulnerability in the CalendarInvite feature of the Zimbra webmail classic user interface. An attacker can exploit this vulnerability via an email message containing a crafted calendar header, leading to the execution of arbitrary JavaScript code.
Impact Analysis
Exploitation Probability (EPSS): 32.4% chance of exploitation in the next 30 days (97th percentile). This is a significantly elevated exploitation probability — prioritize patching.
Is CVE-2024-27443 being exploited?
Yes. CVE-2024-27443 is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, restricted to CVEs with confirmed active exploitation in the wild. CISA added this vulnerability on 2025-05-19. Inclusion in KEV triggers the patching mandate under BOD 22-01 for U.S. federal civilian agencies, with a remediation deadline of 2025-06-09.
How to fix CVE-2024-27443
Apply the security update issued by Synacor for Zimbra Collaboration Suite (ZCS). If an immediate patch is not possible, consult the vendor advisory for mitigation guidance, restrict network exposure of the affected service, and monitor logs for indicators of exploitation. CISA's Known Exploited Vulnerabilities catalog requires U.S. federal agencies to remediate this vulnerability by the due date shown below under Binding Operational Directive 22-01. Private organizations should treat KEV entries as priority-one patches because active exploitation has been confirmed in the wild.
Related Vulnerabilities
Other actively exploited vulnerabilities affecting Zimbra Collaboration Suite (ZCS):
- CVE-2025-48700 (Medium 6.1) [same product] — An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0…
- CVE-2025-66376 (High 7.2) [same product] — Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows…
- CVE-2025-68645 (High 8.8) [same product] — A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of…
- CVE-2025-27915 (Unknown N/A) [same product] — Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting…
- CVE-2019-9621 (High 7.5) [same product] — Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10…
Frequently asked questions
Is CVE-2024-27443 critical?
CVE-2024-27443 has a CVSS 3.1 base score of N/A — Unknown severity. Prioritize based on exposure and the active exploitation signal from the KEV listing.
Is CVE-2024-27443 being actively exploited?
Yes — CISA added CVE-2024-27443 to the Known Exploited Vulnerabilities catalog on 2025-05-19. Inclusion in KEV means CISA has confirmed in-the-wild exploitation.
How do I patch CVE-2024-27443?
Apply the security update from Synacor for Zimbra Collaboration Suite (ZCS). Federal agencies must remediate by 2025-06-09 under BOD 22-01.
What is the CVSS score for CVE-2024-27443?
CVE-2024-27443 has a CVSS 3.1 base score of N/A, classifying it as Unknown severity.