Vulnerability record · CVE-2020-7796 · published 18 February 2020
CVE-2020-7796: Zimbra Collaboration Suite WebEx zimlet SSRF
SSynacor · Zimbra Collaboration Suite
Zimbra Collaboration Suite before 8.8.15 Patch 7 is vulnerable to server-side request forgery when the WebEx zimlet is installed and its JSP is enabled. The flaw lets an unauthenticated remote attacker make the server issue requests to arbitrary destinations, which matters because Zimbra is an internet-facing mail and collaboration platform.
Description
Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, CISA KEV listing with a near-term due date, and a 99.7th percentile EPSS score indicate severe, likely exploited risk.
What it is
Zimbra Collaboration Suite before 8.8.15 Patch 7 is vulnerable to server-side request forgery when the WebEx zimlet is installed and its JSP is enabled. The flaw lets an unauthenticated remote attacker make the server issue requests to arbitrary destinations, which matters because Zimbra is an internet-facing mail and collaboration platform.
Impact
An attacker can force the Zimbra server to send requests to internal or external systems, enabling access to internal services and data that are not directly reachable. The CVSS vector rates confidentiality, integrity and availability impact as high.
Attack surface
Reachable over the network with no authentication and no user interaction (CVSS:3.1/AV:N/AC:L/PR:N/UI:N), but only when the WebEx zimlet is installed and zimlet JSP is enabled.
Exploitation
CVE-2020-7796 is listed in CISA KEV with a due date of 2026-03-10, and EPSS gives a 30-day probability of 0.84418 (99.7th percentile), indicating active exploitation is expected or observed. No ransomware campaign use is documented.
What to do
- Upgrade to Zimbra Collaboration Suite 8.8.15 Patch 7 or later.
- If patching is not possible, disable or remove the WebEx zimlet and disable zimlet JSP.
- Restrict outbound network access from Zimbra servers to only required destinations.
- Follow CISA KEV required action and BOD 22-01 guidance, or discontinue use if mitigations are unavailable.
Detection
- Monitor Zimbra server outbound HTTP requests for unexpected internal or external destinations.
- Audit zimlet configuration to confirm the WebEx zimlet and zimlet JSP are disabled where not needed.
- Review Zimbra and web server logs for requests to WebEx zimlet JSP endpoints.
- Alert on anomalous server-side request patterns originating from the Zimbra host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-7796 to the Known Exploited Vulnerabilities catalog on 17 February 2026 as "Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 10 March 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.15/P7 | Release NotesVendor Advisory |
| https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.15/P7 | Release NotesVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-7796 | US Government Resource |
Track CVE-2020-7796 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-7796), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.