Vulnerability record · CVE-2019-9621 · published 30 April 2019
CVE-2019-9621: Zimbra Collaboration Suite ProxyServlet server-side request forgery
SSynacor · Zimbra Collaboration Suite
Zimbra Collaboration Suite versions before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.11 patch 3 expose a server-side request forgery flaw in the ProxyServlet component. An unauthenticated remote attacker can make the server issue requests to arbitrary destinations, which matters because Zimbra is an internet-facing mail and collaboration platform and this flaw has been chained with other issues in public exploit write-ups.
Description
Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows SSRF via the ProxyServlet component.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
critical priorityThe flaw is unauthenticated, remotely reachable, has public exploit code and was added to CISA KEV with a near-term remediation deadline.
What it is
Zimbra Collaboration Suite versions before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.11 patch 3 expose a server-side request forgery flaw in the ProxyServlet component. An unauthenticated remote attacker can make the server issue requests to arbitrary destinations, which matters because Zimbra is an internet-facing mail and collaboration platform and this flaw has been chained with other issues in public exploit write-ups.
Impact
An attacker gains the ability to send requests from the Zimbra server to internal or external systems, enabling access to internal services and data that are not directly reachable. The CVSS vector rates confidentiality impact as high with no integrity or availability impact.
Attack surface
Reachable over the network through the ProxyServlet endpoint with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The description does not specify the exact request path or parameters.
Exploitation
CVE-2019-9621 was added to CISA KEV on 2025-07-07 with a due date of 2025-07-28, and EPSS gives a 30-day probability of 0.81037 (99.6th percentile). Multiple references are tagged Exploit, including Packet Storm, Exploit-DB and a Rapid7 Metasploit module, so public exploit code exists.
What to do
- Upgrade to a fixed Zimbra release: 8.6 patch 13 or later, 8.7.11 patch 10 or later, 8.8.10 patch 7 or later, or 8.8.11 patch 3 or later.
- If immediate patching is not possible, apply the vendor mitigations referenced in the Zimbra security advisories and follow CISA BOD 22-01 guidance for cloud services.
- Restrict network egress from Zimbra servers so they cannot reach internal management, metadata or other sensitive services.
- Place Zimbra behind a reverse proxy or WAF and limit exposure of administrative and proxy endpoints to trusted networks.
- Monitor for and remove any web shells or unauthorized changes if compromise is suspected, since this flaw has been used in exploit chains.
Detection
- Review Zimbra ProxyServlet and Autodiscover access logs for requests to unexpected internal IP ranges, localhost, or cloud metadata addresses such as 169.254.169.254.
- Alert on outbound connections originating from Zimbra servers to internal services that are not part of normal mail flow.
- Search for known exploit artifacts and indicators from the public Packet Storm, Exploit-DB and Rapid7 references on Zimbra hosts.
- Correlate Zimbra server process network activity with unusual child processes or file writes that could indicate post-exploitation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-9621 to the Known Exploited Vulnerabilities catalog on 7 July 2025 as "Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 28 July 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-9621 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-9621), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.