Exploited CVEs / By vendor / Synacor

Synacor vulnerabilities actively exploited

18 Synacor CVEs on the CISA Known Exploited Vulnerabilities catalog, newest first. Refreshed daily.

Every CVE below is confirmed exploited in the wild, not just theoretically severe. The newest addition is CVE-2025-48700 (Zimbra Collaboration Suite (ZCS), added 2026-04-20). 5 of the 18 are used in ransomware campaigns. New CISA KEV entries appear here the day they are cataloged; the freshest across all vendors are on exploited this week.

18 exploited CVEs5 ransomware-linked
Senserva AI Opinion and rich prompt for Synacor exploited CVEs

Copy this prompt into Claude, ChatGPT, or Copilot. The facts are included, sourced from this page.

Zimbra Collaboration Suite (ZCS): 16 exploited CVEs

CVEProductAdded to KEVSignals
CVE-2025-48700Zimbra Collaboration Suite (ZCS)2026-04-20CVSS 6.1, EPSS 2%
CVE-2025-66376Zimbra Collaboration Suite (ZCS)2026-03-18CVSS 6.1, EPSS 22%
CVE-2025-68645Zimbra Collaboration Suite (ZCS)2026-01-22CVSS 8.8, EPSS 32%
CVE-2025-27915Zimbra Collaboration Suite (ZCS)2025-10-07CVSS 5.4, EPSS 4%
CVE-2019-9621Zimbra Collaboration Suite (ZCS)2025-07-07CVSS 7.5, EPSS 81%
CVE-2024-27443Zimbra Collaboration Suite (ZCS)2025-05-19CVSS 6.1, EPSS 24%
CVE-2023-34192Zimbra Collaboration Suite (ZCS)2025-02-25CVSS 9.0, EPSS 77%
CVE-2024-45519Zimbra Collaboration Suite (ZCS)2024-10-03CVSS 9.8, EPSS 100%
CVE-2023-37580Zimbra Collaboration Suite (ZCS)2023-07-27CVSS 6.1, EPSS 47%
CVE-2022-27926Zimbra Collaboration Suite (ZCS)2023-04-03CVSS 6.1, EPSS 18%
CVE-2022-41352Zimbra Collaboration Suite (ZCS)2022-10-20CVSS 9.8, EPSS 95%
CVE-2022-27925Zimbra Collaboration Suite (ZCS)2022-08-11ransomware, CVSS 7.2, EPSS 99%
CVE-2022-37042Zimbra Collaboration Suite (ZCS)2022-08-11ransomware, CVSS 9.8, EPSS 92%
CVE-2022-27924Zimbra Collaboration Suite (ZCS)2022-08-04ransomware, CVSS 7.5, EPSS 85%
CVE-2018-6882Zimbra Collaboration Suite (ZCS)2022-04-19ransomware, CVSS 6.1, EPSS 25%
CVE-2019-9670Zimbra Collaboration Suite (ZCS)2022-01-10CVSS 9.8, EPSS 100%

Other Synacor products

CVEProductAdded to KEVSignals
CVE-2020-7796Zimbra Collaboration Suite2026-02-17CVSS 9.8, EPSS 84%
CVE-2022-24682Zimbra Collaborate Suite (ZCS)2022-02-25ransomware, CVSS 6.1, EPSS 31%

Common questions about exploited Synacor CVEs

Which Synacor vulnerabilities are actively exploited?

As of August 2026, 18 Synacor CVEs are on the CISA Known Exploited Vulnerabilities catalog, meaning exploitation in the wild is confirmed. The most-listed products are Zimbra Collaboration Suite (ZCS) (16). 5 are linked to ransomware campaigns.

What is the newest exploited Synacor CVE?

CVE-2025-48700, affecting Zimbra Collaboration Suite (ZCS), added to the CISA KEV catalog on 2026-04-20. This page refreshes daily, so the newest entry is always first in the table.

How urgent are these Synacor CVEs?

KEV listing is the strongest fix-first signal there is: it means confirmed exploitation, not a prediction. Patch these ahead of higher-CVSS issues that nobody is exploiting. Check the vendor advisory (linked below) for fixed versions and workarounds.

Can I ask my own AI about exploited Synacor CVEs?

Yes. This page includes a free copy-paste AI prompt carrying the newest Synacor KEV entries, with CVSS, EPSS, and ransomware context, into Claude, ChatGPT, or Copilot. The data is refreshed twice a day (5 AM and 3 PM US Central).

All vendors, searchable with due dates and CSV export: the exploited-CVE tracker. Every vendor with a page: exploited by vendor.

Most searched on Senserva right now

New to a term on this page? CVE, KB, KEV, CVSS, and EPSS are each explained once, on the Senserva security lexicon. Reference: Microsoft CVE and vulnerability management and the Microsoft patching guide.
Provided as is, without warranty; verify against the vendor advisory before acting. Data notice and terms.