CVE-2019-9621
KEV PoC ×4largeUnauthenticated SSRF in Synacor Zimbra Collaboration Suite ProxyServlet
CISA: Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) Vulnerability
CVE-2019-9621 is a server-side request forgery (SSRF, CWE-918) in the ProxyServlet component of Synacor Zimbra Collaboration Suite, triggerable by an unauthenticated attacker sending crafted HTTP requests to the servlet. By making the Zimbra server issue requests of the attacker's choosing, the attacker can probe or access internal network resources from the server's position, with high confidentiality impact (CVSS 3.1: 7.5, AV:N/PR:N/C:H). Public proof-of-concept code is available, including references that pair the SSRF with an XXE flaw (e.g., a Metasploit module for Zimbra XXE-to-RCE), and Exploit-DB/PacketStorm listings cover both the SSRF and the combined injection chain. Any organization running Zimbra 8.6 before patch 13, 8.7.x before 8.7.11 patch 10, or 8.8.x before 8.8.10 patch 7 / 8.8.11 patch 3 is affected. Exploitation is confirmed in the wild: CISA added the flaw to the KEV catalog on 2025-07-07 due to active exploitation, and related reporting ties Zimbra exploitation to the Earth Lusca threat actor, whose SprySOCKS Linux backdoor has targeted government entities.
What to do: Apply Synacor/Zimbra's vendor patches: 8.6.0 patch 13, 8.7.11 patch 10, 8.8.10 patch 7, or 8.8.11 patch 3 (or later) — noting 8.6/8.7 are legacy releases, so plan migration to a supported version; federal agencies must also comply with BOD 22-01. Because EPSS is very high (81%) and active exploitation is confirmed, prioritize internet-facing Zimbra servers first. Hunt for compromise by reviewing logs for unauthenticated requests to the ProxyServlet/autodiscover endpoints, unexpected outbound connections from the Zimbra host, and signs of Linux backdoors such as SprySOCKS on the mail server.
| Synacor Zimbra Collaboration Suite (ZCS) | 8.6 before patch 13 |
| Synacor Zimbra Collaboration Suite (ZCS) | 8.7.x before 8.7.11 patch 10 |
| Synacor Zimbra Collaboration Suite (ZCS) | 8.8.x before 8.8.10 patch 7 |
| Synacor Zimbra Collaboration Suite (ZCS) | 8.8.x before 8.8.11 patch 3 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows SSRF via the ProxyServlet component.
- Affected
- Synacor Zimbra Collaboration Suite (ZCS)
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- synacor
- Products
- zimbra collaboration suite
- Weakness
- CWE-918
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N