ZeroHour

CVE-2025-68645

KEVlarge

PHP Remote File Inclusion in Synacor Zimbra Collaboration Suite (ZCS)

CISA: Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability

CVSS 3.1
8.8 high
EPSS
49%p99
Published
()
KEV added
AI analysis

Synacor Zimbra Collaboration Suite (ZCS) contains a PHP remote file inclusion (RFI) flaw (CWE-98) reachable through its /h/rest endpoint. By sending crafted requests to /h/rest, a remote attacker can influence the application's internal request dispatching and cause the server to include arbitrary files from the WebRoot directory, potentially exposing sensitive file content or executing attacker-influenced file content reachable there. An attacker who abuses this flaw may gain information disclosure or further compromise of the ZCS server; the available data does not specify authentication requirements or confirm full remote code execution. Any organization running Zimbra Collaboration Suite, especially internet-facing ZCS email and collaboration servers, is potentially affected, though specific affected version ranges were not provided in the available data. The flaw was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2026-01-22, indicating confirmed exploitation in the wild, and EPSS assigns a 49.4% probability of exploitation within 30 days (99th percentile); no public proof-of-concept is known.

What to do: Apply the patched ZCS release per Synacor's/Zimbra's advisory (specific patched versions were not provided in the available data) and follow CISA KEV required actions, including applicable BOD 22-01 guidance for federal agencies. Review access logs for crafted or anomalous requests to /h/rest and restrict internet exposure of ZCS endpoints until the patch is deployed. Ransomware association is unknown, so treat exploitation activity as potentially preparatory to broader compromise.

Affected
Synacor Zimbra Collaboration Suite (ZCS)
Estimated exposure
largetens of thousands of internet-exposed ZCS servers (order of ~50,000) — Public internet-wide scans have historically indexed on the order of tens of thousands of exposed Zimbra servers, and ZCS is broadly deployed as self-hosted email/collaboration infrastructure by enterprises, service providers, and…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper handling of user-supplied request parameters in the RestFilter servlet. An unauthenticated remote attacker can craft requests to the /h/rest endpoint to influence internal request dispatching, allowing inclusion of arbitrary files from the WebRoot directory.

CISA Known Exploited Vulnerability
Affected
Synacor Zimbra Collaboration Suite (ZCS)
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
synacor
Products
zimbra collaboration suite
Weakness
CWE-98
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news