← Vulnerability feed

Vulnerability record · CVE-2019-9621 · published 30 April 2019

CVE-2019-9621: Zimbra Collaboration Suite ProxyServlet server-side request forgery

SSynacor · Zimbra Collaboration Suite

Zimbra Collaboration Suite versions before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.11 patch 3 expose a server-side request forgery flaw in the ProxyServlet component. An unauthenticated remote attacker can make the server issue requests to arbitrary destinations, which matters because Zimbra is an internet-facing mail and collaboration platform and this flaw has been chained with other issues in public exploit write-ups.

7.5 CVSS 3.1 High CISA KEV since 7 Jul 2025 EPSS 81% · top 0.4% CWE-918 · Server-side request forgery (SSRF)
7.5CVSS 3.1 base score, v2 5.0
81%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
19References, 8 tagged exploit
17 Jun 2026Last modified by NVD

Description

Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows SSRF via the ProxyServlet component.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityThe flaw is unauthenticated, remotely reachable, has public exploit code and was added to CISA KEV with a near-term remediation deadline.

What it is

Zimbra Collaboration Suite versions before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.11 patch 3 expose a server-side request forgery flaw in the ProxyServlet component. An unauthenticated remote attacker can make the server issue requests to arbitrary destinations, which matters because Zimbra is an internet-facing mail and collaboration platform and this flaw has been chained with other issues in public exploit write-ups.

Impact

An attacker gains the ability to send requests from the Zimbra server to internal or external systems, enabling access to internal services and data that are not directly reachable. The CVSS vector rates confidentiality impact as high with no integrity or availability impact.

Attack surface

Reachable over the network through the ProxyServlet endpoint with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The description does not specify the exact request path or parameters.

Exploitation

CVE-2019-9621 was added to CISA KEV on 2025-07-07 with a due date of 2025-07-28, and EPSS gives a 30-day probability of 0.81037 (99.6th percentile). Multiple references are tagged Exploit, including Packet Storm, Exploit-DB and a Rapid7 Metasploit module, so public exploit code exists.

What to do

  • Upgrade to a fixed Zimbra release: 8.6 patch 13 or later, 8.7.11 patch 10 or later, 8.8.10 patch 7 or later, or 8.8.11 patch 3 or later.
  • If immediate patching is not possible, apply the vendor mitigations referenced in the Zimbra security advisories and follow CISA BOD 22-01 guidance for cloud services.
  • Restrict network egress from Zimbra servers so they cannot reach internal management, metadata or other sensitive services.
  • Place Zimbra behind a reverse proxy or WAF and limit exposure of administrative and proxy endpoints to trusted networks.
  • Monitor for and remove any web shells or unauthorized changes if compromise is suspected, since this flaw has been used in exploit chains.

Detection

  • Review Zimbra ProxyServlet and Autodiscover access logs for requests to unexpected internal IP ranges, localhost, or cloud metadata addresses such as 169.254.169.254.
  • Alert on outbound connections originating from Zimbra servers to internal services that are not part of normal mail flow.
  • Search for known exploit artifacts and indicators from the public Packet Storm, Exploit-DB and Rapid7 references on Zimbra hosts.
  • Correlate Zimbra server process network activity with unusual child processes or file writes that could indicate post-exploitation.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2019-9621 to the Known Exploited Vulnerabilities catalog on 7 July 2025 as "Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 28 July 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/152487/Zimbra-Collaboration-Autodiscover-Servlet-XXE-ProxyServlet-SSRF.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/153190/Zimbra-XML-Injection-Server-Side-Request-Forgery.html ExploitThird Party AdvisoryVDB Entry
http://www.rapid7.com/db/modules/exploit/linux/http/zimbra_xxe_rce ExploitThird Party Advisory
https://blog.tint0.com/2019/03/a-saga-of-code-executions-on-zimbra.html Third Party Advisory
https://blog.zimbra.com/2019/03/9826/ Vendor Advisory
https://bugzilla.zimbra.com/show_bug.cgi?id=109127 Issue Tracking
https://wiki.zimbra.com/wiki/Security_Center Release NotesVendor Advisory
https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories Vendor Advisory
https://www.exploit-db.com/exploits/46693/ ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/152487/Zimbra-Collaboration-Autodiscover-Servlet-XXE-ProxyServlet-SSRF.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/153190/Zimbra-XML-Injection-Server-Side-Request-Forgery.html ExploitThird Party AdvisoryVDB Entry
http://www.rapid7.com/db/modules/exploit/linux/http/zimbra_xxe_rce ExploitThird Party Advisory
https://blog.tint0.com/2019/03/a-saga-of-code-executions-on-zimbra.html Third Party Advisory
https://blog.zimbra.com/2019/03/9826/ Vendor Advisory
https://bugzilla.zimbra.com/show_bug.cgi?id=109127 Issue Tracking
https://wiki.zimbra.com/wiki/Security_Center Release NotesVendor Advisory
https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories Vendor Advisory
https://www.exploit-db.com/exploits/46693/ ExploitThird Party AdvisoryVDB Entry
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-9621 US Government Resource

Track CVE-2019-9621 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-45519Zimbra Collaboration postjournal service unauthenticated command executionThe postjournal service in Zimbra Collaboration Suite fails to properly neutralize input, allowing OS command injection. Because the service can be r…KEVEPSS 100%analysed9.8CVE-2022-41352Zimbra Collaboration amavis cpio path traversal arbitrary file uploadZimbra Collaboration Suite 8.8.15 and 9.0 allow an attacker to upload arbitrary files through amavis by abusing cpio archive extraction into the web-…KEVEPSS 95%analysed9.8CVE-2022-37042Zimbra Collaboration Suite mboximport auth bypass path traversal RCEZimbra Collaboration Suite 8.8.15 and 9.0 mboximport accepts a ZIP archive and extracts files without requiring an authtoken, allowing unauthenticate…KEVEPSS 92%analysed9.8CVE-2020-7796Zimbra Collaboration Suite WebEx zimlet SSRFZimbra Collaboration Suite before 8.8.15 Patch 7 is vulnerable to server-side request forgery when the WebEx zimlet is installed and its JSP is enabl…KEVEPSS 84%analysed9.8CVE-2019-9670Zimbra mailboxd Autodiscover XXE allows unauthenticated compromiseThe mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 parses XML in the Autodiscover servlet without restricting extern…KEVEPSS 100%analysed9.0CVE-2023-34192Zimbra ZCS autoSaveDraft XSS enables remote code executionZimbra Collaboration Suite 8.8.15 has a cross-site scripting flaw in the /h/autoSaveDraft function. A remote authenticated attacker can inject a craf…KEVEPSS 77%analysed8.9CVE-2026-73570Zimbra Collaboration SNMP notification OS command injectionZimbra Collaboration Suite before 10.1.20 contains an OS command injection flaw in SNMP notification processing when the optional zimbra-snmp package…KEVEPSS 12%analysed8.8CVE-2025-68645Zimbra Webmail Classic UI RestFilter local file inclusionZimbra Collaboration Suite 10.0 and 10.1 mishandle user-supplied parameters in the RestFilter servlet of the Webmail Classic UI, allowing local file …KEVEPSS 49%analysed

Source: NIST National Vulnerability Database (record CVE-2019-9621), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.