CVE-2025-68645 — Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability
2026-01-22 • CISA Known Exploited Vulnerability
[event] Synacor Zimbra Collaboration Suite (ZCS) contains a PHP remote file inclusion vulnerability that could allow for remote attackers to craft requests to the /h/rest endpoint to influence internal request dispatching, allowing inclusion of arbitrary files from the WebRoot directory.
> AFFECTED SOFTWARE
| Field | Value |
|---|---|
| Vendor | Synacor |
| Product | Zimbra Collaboration Suite (ZCS) |
| CWE | CWE-98 |
| CVE ID | CVE-2025-68645 |
| Date Added | 2026-01-22 |
| Due Date | 2026-02-12 |
| Ransomware Campaign | Unknown |
> MITIGATION
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due Date: 2026-02-12