CVE-2025-32354: Synacor Zimbra Collaboration Suite

High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.

In Zimbra Collaboration (ZCS) 9.0 through 10.1, a Cross-Site Request Forgery (CSRF) vulnerability exists in the GraphQL endpoint (/service/extension/graphql) of Zimbra webmail due to a lack of CSRF token validation. This allows attackers to perform unauthorized GraphQL operations, such as modifying contacts, changing account settings, and accessing sensitive user data when an authenticated user visits a malicious website.

Affected products

  • Synacor Zimbra Collaboration Suite: from 9.0.0, before 10.1.4 (fixed in 10.1.4)

Published 2025-04-29. Last modified 2026-06-17.