CISA says multiple vulnerabilities in Synacor Zimbra Collaboration Suite (ZCS) are being widely exploited.

CISA says multiple vulnerabilities in Synacor Zimbra Collaboration Suite (ZCS) are being widely exploited.

The popularity of Synacor Zimbra Collaboration Suite (ZCS) has made it a frequent target for cyberattacks, particularly those exploiting Server-Side Request Forgery (SSRF) vulnerabilities. SSRF flaws can allow attackers to manipulate the server into making unauthorized requests to internal or external systems, potentially exposing sensitive data or enabling further exploitation such as remote code execution (RCE). Today, CISA added CVE-2019-9621 (an SSRF vulnerability in ZCS) to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation.