PatchSiren cyber security CVE debrief
CVE-2024-27443 Synacor CVE debrief
CVE-2024-27443 affects Synacor Zimbra Collaboration Suite (ZCS) and is listed in CISA's Known Exploited Vulnerabilities catalog. The CISA entry points to vendor security-fix releases for Zimbra 8.8.15 P46, 9.0.0 P39, and 10.0.7, and sets a mitigation deadline of 2025-06-09. Organizations running ZCS should prioritize remediation and confirm exposure as soon as possible.
- Vendor
- Synacor
- Product
- Zimbra Collaboration Suite (ZCS)
- CVSS
- Unknown
- CISA KEV
- Listed
- Original CVE published
- 2025-05-19
- Original CVE updated
- 2025-05-19
- Advisory published
- 2025-05-19
- Advisory updated
- 2025-05-19
Who should care
Email and collaboration platform administrators, security operations teams, and vulnerability managers responsible for Synacor Zimbra Collaboration Suite (ZCS) deployments.
Technical summary
The supplied corpus identifies CVE-2024-27443 as a cross-site scripting (XSS) vulnerability in Synacor Zimbra Collaboration Suite (ZCS). CISA added it to the Known Exploited Vulnerabilities catalog on 2025-05-19 and references vendor security-fix releases for 8.8.15 P46, 9.0.0 P39, and 10.0.7. The corpus does not provide a CVSS score or additional exploitation details.
Defensive priority
Urgent
Recommended defensive actions
- Inventory all Synacor Zimbra Collaboration Suite (ZCS) instances across production, test, and externally reachable environments.
- Apply the vendor security fixes referenced by CISA for the applicable ZCS release train: 8.8.15 P46, 9.0.0 P39, or 10.0.7.
- If mitigations cannot be applied promptly, follow CISA's KEV guidance to mitigate per vendor instructions, follow BOD 22-01 for cloud services where applicable, or discontinue use if mitigations are unavailable.
- Verify that remediation is complete on all exposed ZCS systems and that the vulnerable condition is no longer present.
- Track closure against the CISA KEV due date of 2025-06-09 and document evidence of remediation.
Evidence notes
Source corpus and official links identify CVE-2024-27443 as a Zimbra Collaboration Suite XSS issue added to CISA KEV on 2025-05-19 with a mitigation due date of 2025-06-09. The CISA KEV source item references Synacor/Zimbra security-fix pages for 8.8.15 P46, 9.0.0 P39, and 10.0.7, plus the NVD detail page. The corpus does not supply a CVSS score, and ransomware-campaign use is marked Unknown.
Official resources
-
CVE-2024-27443 CVE record
CVE.org
-
CVE-2024-27443 NVD detail
NVD
-
CISA Known Exploited Vulnerabilities catalog
CISA - Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
-
Source item URL
cisa_kev
Publicly disclosed and included in CISA's Known Exploited Vulnerabilities catalog on 2025-05-19.