CVE-2024-45519: Synacor Zimbra Collaboration Suite (ZCS) Command Execution Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2024-10-03. EPSS: 99.9% chance of exploitation in the next 30 days.
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1 sometimes allows unauthenticated users to execute commands.
Affected products
- Synacor Zimbra Collaboration Suite: before 8.8.15 (fixed in 8.8.15); from 10.0.0, before 10.0.9 (fixed in 10.0.9); version 8.8.15 only; version 9.0.0 only; version 10.1.0 only
Published 2024-10-02. Last modified 2026-06-17.