CVE-2025-68645
Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 12 February 2026). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper handling of user-supplied request parameters in the RestFilter servlet. An unauthenticated remote attacker can craft requests to the /h/rest endpoint to influence internal request dispatching, allowing inclusion of arbitrary files from the WebRoot directory.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 49.37% probability · 99th percentile
- CISA KEV
- Listed 22 January 2026 · due 12 February 2026
- Weakness
- CWE-98
- Affected
- synacor/zimbra collaboration suite
- Source
- cve@mitre.org
CISA notes
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://wiki.zimbra.com/wiki/Security_Center ; https://nvd.nist.gov/vuln/detail/CVE-2025-68645
References
- https://wiki.zimbra.com/wiki/Security_CenterRelease Notes, Vendor Advisory
- https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_PolicyProduct
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-68645US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.