Exploited Known exploited (KEV) CVE-2025-48700

A three-day window: cross-site scripting in a mail platform listed 17 times

Synacor Zimbra Collaboration Suite (ZCS) Added to KEV Apr 20, 2026 Federal remediation due 2026-04-23

Added on 20 April 2026 with a remediation date of 23 April. A three-day window occurs in only 101 of the 1,695 KEV records kept here. Zimbra appears in the catalog 17 times.

Key facts

  • CVE IDCVE-2025-48700
  • Affected (vendor / product)Synacor Zimbra Collaboration Suite (ZCS)
  • CWECWE-79
  • ExploitationListed in CISA KEV (exploitation confirmed)
  • Remediation due2026-04-23 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • A cross-site scripting flaw in Zimbra Collaboration Suite allowing arbitrary JavaScript inside a user session.
  • Added 20 April 2026 with a 23 April deadline: a three-day window.
  • Only 101 of 1,695 records (6.0%) have a window of three days or less; the largest band is 15 to 21 days at 1,025 (60.5%).
  • Zimbra appears 17 times, eight of them the same cross-site scripting weakness.

1Three days

The previous article had a window of twenty-one days. This one has three. Of the 1,695 KEV records this site holds as of 2026-09-06, only 101 (6.0%) carry a window of three days or less.

Window on this record3 daysadded 20 April 2026, due 23 April
Records with a window of three days or less1016.0% of 1,695
The most common band15 to 21 days1,025 records (60.5%)

The length of a window is not set by severity alone. What it does change is practice: a short window leaves little room to sequence the response.

2The same type recurring in the same product

Splitting Zimbra's 17 entries by weakness type, nearly half are the same cross-site scripting flaw (CWE-79).

Cross-site scripting (CWE-79)8 / 17
Path traversal (CWE-22)2 / 17
Others (SSRF, code injection and more)7 / 17

Identifier years run from 2018 to 2026, with five from 2022 the largest single year. In collaboration platforms with a web interface, the same input-handling family recurs.

3What can happen

Cross-site scripting lets an attacker's script run in a legitimate user's browser with the privileges of the site. Here the record describes arbitrary JavaScript executing within a user session, potentially reaching sensitive information. A mail platform is a screen reached after authentication, so a script running there sees what the user sees.

The next article takes up a product listed exactly twice.

Why it matters

A remediation deadline works directly as a priority signal. Records with a window of a few days will not fit ordinary change management, so an emergency path has to exist in advance.

FAQ

What sets the length of the window?
The record does not state a rule. What can be confirmed here is the distribution: 6.0% at three days or less, 60.5% between fifteen and twenty-one days.
Why does cross-site scripting matter?
It runs an attacker script in a legitimate browser with the privileges of the site. On a screen reached after authentication, it sees what the user sees.
Why does one product repeat the same weakness type?
The record does not explain it. The fact is that eight of Zimbra 17 entries share the type.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#KEV#Known exploited#Zimbra#Cross-site scripting#Remediation deadline
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.