ZeroHour

CVE-2020-7796

KEVlarge

Unauthenticated SSRF in Synacor Zimbra Collaboration Suite (CVE-2020-7796)

CISA: Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability

CVSS 3.1
9.8 critical
EPSS
84%p100
Published
()
KEV added
AI analysis

CVE-2020-7796 is a server-side request forgery (SSRF, CWE-918) in Synacor Zimbra Collaboration Suite (ZCS) versions before 8.8.15 Patch 7, rated critical at CVSS 9.8 with network reachability and no authentication or privileges required. The flaw is triggered when the WebEx zimlet is installed and zimlet JSP processing is enabled, allowing an unauthenticated remote attacker to make the Zimbra server issue attacker-controlled requests. Successful SSRF can let the attacker reach internal network services from the mail server's position (e.g., internal admin interfaces or other hosts behind the firewall), potentially leading to information disclosure or further compromise, and the CVSS vector indicates high impact to confidentiality, integrity, and availability. Any organization running a vulnerable Zimbra version with the WebEx zimlet present is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-02-17, confirming active exploitation, and it carries a very high EPSS score (84.4%, top percentile) amid a reported coordinated surge in SSRF exploitation activity.

What to do: Upgrade Zimbra Collaboration Suite to 8.8.15 Patch 7 or later. If patching must be delayed, remove or disable the WebEx zimlet and disable zimlet JSP processing to eliminate the trigger; first check whether the WebEx zimlet is installed, since instances without it are not exposed to this specific flaw. As a KEV entry, federal agencies must apply vendor mitigations per BOD 22-01 (or discontinue use if unavailable), and all operators should review Zimbra logs for unauthenticated requests reaching zimlet JSP endpoints.

Affected
Synacor Zimbra Collaboration Suite (ZCS)before 8.8.15 Patch 7 (exploitable only when the WebEx zimlet is installed and zimlet JSP is enabled)
Estimated exposure
largetens of thousands of internet-exposed Zimbra servers (public internet scans); the exploitable subset with the WebEx zimlet installed is smaller and of unknown… — Internet-wide scans have historically shown Zimbra deployments numbering in the tens of thousands, and Zimbra is widely used by enterprises, governments, and service providers, but the share of those instances that also have the WebEx…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled.

CISA Known Exploited Vulnerability
Affected
Synacor Zimbra Collaboration Suite
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
synacor
Products
zimbra collaboration suite
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news