CVE-2019-9621
synacor zimbra collaboration suite
Published 30 Apr 2019 · updated 17 Jun 2026 · Analyzed
7.5 High · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 7 Jul 2025, with a remediation deadline of 28 Jul 2025 for US federal agencies.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Description
Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows SSRF via the ProxyServlet component.
References
- packetstormsecurity.com/files/152487/Zimbra-Collaboration-Autodiscover-Servlet-XXE-ProxyServlet-SSRF.html · Exploit, Third Party Advisory, VDB Entry
- packetstormsecurity.com/files/153190/Zimbra-XML-Injection-Server-Side-Request-Forgery.html · Exploit, Third Party Advisory, VDB Entry
- www.rapid7.com/db/modules/exploit/linux/http/zimbra_xxe_rce · Exploit, Third Party Advisory
- blog.tint0.com/2019/03/a-saga-of-code-executions-on-zimbra.html · Third Party Advisory
- blog.zimbra.com/2019/03/9826/ · Vendor Advisory
- bugzilla.zimbra.com/show_bug.cgi?id=109127 · Issue Tracking
- wiki.zimbra.com/wiki/Security_Center · Release Notes, Vendor Advisory
- wiki.zimbra.com/wiki/Zimbra_Security_Advisories · Vendor Advisory
- www.exploit-db.com/exploits/46693/ · Exploit, Third Party Advisory, VDB Entry
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-9621 · US Government Resource