Disclosure summary
Synacor Zimbra Collaboration Suite (ZCS) contains flaw in the mboximport functionality, allowing an authenticated attacker to upload arbitrary files to perform remote code execution. This vulnerability was chained with CVE-2022-37042 which allows for unauthenticated remote code execution.
CISA remediation guidance
Apply updates per vendor instructions.
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
Rapid7 Blog · RSS-087d9d059be8baf7b6734d576c5516c0ae3
Open original source · Updated Sep 24, 2026
When Business Email Compromise Starts Rewriting Reality
CVE mention in publisher metadata; check the original affected versions.
Original records & references
PUBLISHED 2022-08-11T00:00:00-04:00
MODIFIED 2022-08-11T00:00:00-04:00
INGESTED 2026-10-06T11:42:58-04:00