PatchSiren cyber security CVE debrief
CVE-2025-48700 Synacor CVE debrief
CVE-2025-48700 is listed by CISA as a known exploited vulnerability affecting Synacor Zimbra Collaboration Suite (ZCS). The supplied corpus identifies it as a cross-site scripting issue and sets a CISA due date of 2026-04-23 for remediation planning. Because the available record is a KEV entry rather than a full vendor advisory, defenders should treat it as urgent and rely on official vendor guidance for mitigation details.
- Vendor
- Synacor
- Product
- Zimbra Collaboration Suite (ZCS)
- CVSS
- Unknown
- CISA KEV
- Listed
- Original CVE published
- 2026-04-20
- Original CVE updated
- 2026-04-20
- Advisory published
- 2026-04-20
- Advisory updated
- 2026-04-20
Who should care
Organizations running Synacor Zimbra Collaboration Suite (ZCS), especially messaging, collaboration, and security teams responsible for patching or mitigation.
Technical summary
CISA's Known Exploited Vulnerabilities catalog identifies CVE-2025-48700 as a cross-site scripting vulnerability in Synacor Zimbra Collaboration Suite (ZCS). The catalog entry marks it as known exploited and instructs defenders to apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. The supplied corpus does not include CVSS metrics, affected versions, or additional technical details.
Defensive priority
Urgent. This is a CISA KEV-listed issue with a near-term due date, so remediation or mitigation should be prioritized immediately.
Recommended defensive actions
- Review Synacor/Zimbra official security guidance and apply the vendor-recommended mitigation or fix as soon as possible.
- If a mitigation is not available, follow CISA guidance and discontinue use of the product until the risk can be reduced.
- For cloud-hosted deployments, follow applicable BOD 22-01 guidance.
- Track remediation against the CISA KEV due date of 2026-04-23 and verify that all ZCS instances are covered.
Evidence notes
The supplied corpus contains a CISA KEV JSON entry dated 2026-04-20 for CVE-2025-48700, naming it as a Synacor Zimbra Collaboration Suite (ZCS) cross-site scripting vulnerability and marking it as known exploited. It also supplies the CISA-required action text and links to the CVE record, NVD detail page, and CISA KEV catalog. No CVSS score, affected-version list, or vendor advisory text was provided.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-48700 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-48700
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-48700 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-48700
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
-
CISA Known Exploited Vulnerabilities catalog
Publisher, destination, and source semantics verified
URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
cisa_kev
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.