🔴
CISA KEV Alert — Active Real-World Exploitation Confirmed
This vulnerability is in the CISA Known Exploited Vulnerabilities catalog and is being actively exploited right now.
Synacor Zimbra Collaboration Suite XSS (CVE-2025-48700) | MSSP Advisory
High🔴 KEV ALERT
DateMay 6, 2026
CVECVE-2025-48700
CVSS Score6.1
Affectedzimbra_collaboration_suite
📋Executive Summary
CISA added a cross-site scripting vulnerability in Zimbra Collaboration Suite to their Known Exploited Vulnerabilities catalog. Active exploitation means attackers can execute JavaScript in user sessions to steal credentials and gain unauthorized access to email systems.
⚠️Why It Matters for MSSPs
Your RMM and PSA likely connect to client Zimbra instances for email security monitoring, creating a direct path from compromised email to your management stack. Client organizations running Zimbra face immediate session hijacking risks that will generate incident response demands within hours of successful exploitation.
✅Recommended Action
Audit all client environments for Zimbra deployments today and push emergency patching communications before end of business. Temporarily restrict RMM access to Zimbra systems until patches are verified deployed across your client base.
🔒Get your first advisory free →
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
🏷️Threat Category
Vulnerability Disclosure
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.