CVE-2019-9621: Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) Vulnerability

High severity, CVSS 7.5. Actively exploited: in CISA KEV since 2025-07-07. EPSS: 81% chance of exploitation in the next 30 days.

Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows SSRF via the ProxyServlet component.

Affected products

  • Synacor Zimbra Collaboration Suite: before 8.6.0 (fixed in 8.6.0); from 8.7.0, before 8.7.11 (fixed in 8.7.11); from 8.8.0, before 8.8.9 (fixed in 8.8.9); version 8.6.0 only; version 8.7.11 only; version 8.8.9 only; …

Published 2019-04-30. Last modified 2026-06-17.