Zimbra collaboration suite (zcs)
This hub aggregates every CVE we track for Zimbra collaboration suite (zcs), a product in the communications space. Use it to gauge the current risk picture and drill into individual advisories.
5
CVEs tracked
4
Critical
1
High
0
In CISA KEV
Severity distribution
CRITICAL4HIGH1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
4
2024-102026-09
Latest CVEs
The 5 most recently published vulnerabilities affecting Zimbra collaboration suite (zcs).
- CVE-2026-93647Zimbra Collaboration Suite Classic Web Client Stored Cross-Site Scripting via Crafted Calendar COUNTER Message From Address9.3
- CVE-2026-93643Zimbra Collaboration Suite OnlyOffice Integration Path Traversal Leading to Remote Code Execution via Unauthenticated /downloadas Request9.8
- CVE-2026-93642Zimbra Collaboration Suite Modern Web Client Stored Cross-Site Scripting via Forged Share Invitation9.3
- CVE-2026-93641Zimbra Collaboration Suite Classic Web Client Stored Cross-Site Scripting via Forged Share Invitation9.3
- CVE-2022-3569Due to an issue with incorrect sudo permissions, Zimbra Collaboration Suite (ZCS) suffers from a local privilege escalation issue in versions 9.0.0 and prior, where the 'zimbra' user can effectivel...7.8
Product normalization is registry-driven with AI assist and human review. How it works