PatchSiren

PatchSiren cyber security CVE debrief

CVE-2022-27925 Synacor CVE debrief

CVE-2022-27925 is a Synacor Zimbra Collaboration Suite (ZCS) vulnerability that CISA has classified as a Known Exploited Vulnerability (KEV). The public record describes it as an arbitrary file upload issue, and CISA’s notes also point to a Zimbra advisory discussing an authentication bypass in mailboxImportServlet. Because it is already in the KEV catalog and marked with known ransomware campaign use, defenders should treat it as urgent and apply vendor-directed updates immediately.

Vendor
Synacor
Product
Zimbra Collaboration Suite (ZCS)
CVSS
HIGH 7.2
CISA KEV
Listed
Original CVE published
2022-08-11
Original CVE updated
2022-08-11
Advisory published
2022-08-11
Advisory updated
2022-08-11

Who should care

Organizations running Synacor Zimbra Collaboration Suite (ZCS), especially internet-facing mail systems; security operations teams; IT administrators; and managed service providers responsible for patching and monitoring Zimbra deployments.

Technical summary

The supplied records identify CVE-2022-27925 as a Zimbra Collaboration Suite vulnerability involving arbitrary file upload. CISA’s KEV entry confirms active exploitation and notes a related Zimbra advisory about an authentication bypass in mailboxImportServlet. The combination of file-upload risk, public exploitation, and known ransomware campaign use makes exposed ZCS instances especially sensitive to compromise.

Defensive priority

Urgent

Recommended defensive actions

  • Apply updates per vendor instructions for Zimbra Collaboration Suite (ZCS) as soon as possible.
  • Inventory all ZCS instances, including externally reachable mail servers and test or standby systems.
  • Verify which hosts are exposed to the internet and prioritize those for immediate remediation.
  • Review authentication, upload, and application logs for suspicious activity around the affected time window.
  • If compromise is suspected, initiate incident response and hunt for unauthorized files, accounts, or web shell-like artifacts.
  • Track CISA KEV guidance and validate that remediation is completed before the KEV due date for affected systems.

Evidence notes

CVE-2022-27925 was published on 2022-08-11 and the CISA KEV entry was added the same day. The CVE title/description in the supplied corpus identify an arbitrary file upload vulnerability in Synacor Zimbra Collaboration Suite (ZCS). CISA’s KEV metadata marks known ransomware campaign use as 'Known' and directs defenders to apply updates per vendor instructions. The KEV notes also reference a Zimbra blog advisory about an authentication bypass in mailboxImportServlet, while the supplied NVD and CVE.org links provide the official vulnerability records.

Sources and references

Verified primary and authoritative sources

  • CVE-2022-27925 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2022-27925

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2022-27925 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2022-27925

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

  • CISA Known Exploited Vulnerabilities catalog

    Publisher, destination, and source semantics verified

    URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

    Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json

    cisa_kev

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.