Actively Exploited — CISA KEV
CVE-2025-27915: Synacor Zimbra Collaboration Suite (ZCS) Vulnerability
Severity: Unknown | CVSS 3.1: N/A | KEV Added: 2025-10-07
What is CVE-2025-27915?
Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that exists in the Classic Web Client due to insufficient sanitization of HTML content in ICS files. When a user views an e-mail message containing a malicious ICS entry, its embedded JavaScript executes via an ontoggle event inside a tag. This allows an attacker to run arbitrary JavaScript within the victim's session, potentially leading to unauthorized actions such as setting e-mail filters to redirect messages to an attacker-controlled address. As a result, an attacker can perform unauthorized actions on the victim's account, including e-mail redirection and data exfiltration.
Impact Analysis
Exploitation Probability (EPSS): 26.1% chance of exploitation in the next 30 days (96th percentile). This is a significantly elevated exploitation probability — prioritize patching.
Is CVE-2025-27915 being exploited?
Yes. CVE-2025-27915 is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, restricted to CVEs with confirmed active exploitation in the wild. CISA added this vulnerability on 2025-10-07. Inclusion in KEV triggers the patching mandate under BOD 22-01 for U.S. federal civilian agencies, with a remediation deadline of 2025-10-28.
How to fix CVE-2025-27915
Apply the security update issued by Synacor for Zimbra Collaboration Suite (ZCS). If an immediate patch is not possible, consult the vendor advisory for mitigation guidance, restrict network exposure of the affected service, and monitor logs for indicators of exploitation. CISA's Known Exploited Vulnerabilities catalog requires U.S. federal agencies to remediate this vulnerability by the due date shown below under Binding Operational Directive 22-01. Private organizations should treat KEV entries as priority-one patches because active exploitation has been confirmed in the wild.
Related Vulnerabilities
Other actively exploited vulnerabilities affecting Zimbra Collaboration Suite (ZCS):
- CVE-2025-48700 (Medium 6.1) [same product] — An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0…
- CVE-2025-66376 (High 7.2) [same product] — Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows…
- CVE-2025-68645 (High 8.8) [same product] — A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of…
- CVE-2019-9621 (High 7.5) [same product] — Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10…
- CVE-2024-27443 (Unknown N/A) [same product] — Zimbra Collaboration contains a cross-site scripting (XSS) vulnerability in…
Frequently asked questions
Is CVE-2025-27915 critical?
CVE-2025-27915 has a CVSS 3.1 base score of N/A — Unknown severity. Prioritize based on exposure and the active exploitation signal from the KEV listing.
Is CVE-2025-27915 being actively exploited?
Yes — CISA added CVE-2025-27915 to the Known Exploited Vulnerabilities catalog on 2025-10-07. Inclusion in KEV means CISA has confirmed in-the-wild exploitation.
How do I patch CVE-2025-27915?
Apply the security update from Synacor for Zimbra Collaboration Suite (ZCS). Federal agencies must remediate by 2025-10-28 under BOD 22-01.
What is the CVSS score for CVE-2025-27915?
CVE-2025-27915 has a CVSS 3.1 base score of N/A, classifying it as Unknown severity.