PatchSiren

PatchSiren cyber security CVE debrief

CVE-2016-3413 Synacor CVE debrief

CVE-2016-3413 is an unspecified vulnerability in Zimbra Collaboration before 8.7.0 that can let a remote attacker affect integrity through unknown vectors. The public record does not disclose the exact flaw, but the machine-readable NVD data shows the issue is network-reachable, requires no privileges or user interaction, and is rated as high integrity impact. For organizations running Zimbra, this is a patch-priority issue because the public record ties exposure to versions up to 8.6.0 inclusive and points to vendor release and advisory pages for remediation.

Vendor
Synacor
Product
Zimbra Collaboration Suite
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2017-01-18
Original CVE updated
2026-05-13
Advisory published
2017-01-18
Advisory updated
2026-05-13

Who should care

Zimbra Collaboration administrators, email and messaging platform security teams, MSPs managing Zimbra deployments, and incident responders responsible for integrity-sensitive mail infrastructure.

Technical summary

NVD maps CVE-2016-3413 to Synacor/Zimbra Collaboration versions through 8.6.0 inclusive. The CVSS 3.0 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N, indicating remote exploitability with no required privileges or user interaction and a primary integrity impact. The public description does not identify the root cause or a specific CWE beyond NVD-CWE-noinfo.

Defensive priority

High for any Zimbra Collaboration deployment at or below 8.6.0; prioritize internet-facing and business-critical systems for immediate remediation.

Recommended defensive actions

  • Upgrade Zimbra Collaboration to 8.7.0 or later, following the vendor release notes referenced in the CVE record.
  • Inventory all Zimbra instances and verify that no deployment remains at 8.6.0 or earlier.
  • Review Zimbra Security Advisories for related fixes and apply them promptly to all supported environments.
  • After remediation, validate the integrity of critical Zimbra configuration and data, and review logs for unexpected changes around the affected period.
  • If patching must be delayed, reduce exposure by limiting network access to Zimbra services and monitoring for anomalous administrative or configuration activity.

Evidence notes

The CVE record and NVD detail page describe an unspecified integrity issue in Zimbra Collaboration before 8.7.0. NVD lists the vulnerable CPE range as synacor:zimbra_collaboration_suite through 8.6.0 inclusive and assigns CVSS 3.0 AV:N/AC:L/PR:N/UI:N/C:N/I:H/A:N. NVD also records NVD-CWE-noinfo, so the root cause is not publicly classified. The CVE references include Zimbra Releases/8.7.0 and Zimbra Security Advisories, which support the version boundary and remediation context.

Sources and references

Verified primary and authoritative sources

  • CVE-2016-3413 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2016-3413

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2016-3413 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2016-3413

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.