CVE-2020-7796
KEVlargeUnauthenticated SSRF in Synacor Zimbra Collaboration Suite (CVE-2020-7796)
CISA: Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability
CVE-2020-7796 is a server-side request forgery (SSRF, CWE-918) in Synacor Zimbra Collaboration Suite (ZCS) versions before 8.8.15 Patch 7, rated critical at CVSS 9.8 with network reachability and no authentication or privileges required. The flaw is triggered when the WebEx zimlet is installed and zimlet JSP processing is enabled, allowing an unauthenticated remote attacker to make the Zimbra server issue attacker-controlled requests. Successful SSRF can let the attacker reach internal network services from the mail server's position (e.g., internal admin interfaces or other hosts behind the firewall), potentially leading to information disclosure or further compromise, and the CVSS vector indicates high impact to confidentiality, integrity, and availability. Any organization running a vulnerable Zimbra version with the WebEx zimlet present is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-02-17, confirming active exploitation, and it carries a very high EPSS score (84.4%, top percentile) amid a reported coordinated surge in SSRF exploitation activity.
What to do: Upgrade Zimbra Collaboration Suite to 8.8.15 Patch 7 or later. If patching must be delayed, remove or disable the WebEx zimlet and disable zimlet JSP processing to eliminate the trigger; first check whether the WebEx zimlet is installed, since instances without it are not exposed to this specific flaw. As a KEV entry, federal agencies must apply vendor mitigations per BOD 22-01 (or discontinue use if unavailable), and all operators should review Zimbra logs for unauthenticated requests reaching zimlet JSP endpoints.
| Synacor Zimbra Collaboration Suite (ZCS) | before 8.8.15 Patch 7 (exploitable only when the WebEx zimlet is installed and zimlet JSP is enabled) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled.
- Affected
- Synacor Zimbra Collaboration Suite
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- synacor
- Products
- zimbra collaboration suite
- Weakness
- CWE-918
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H