CVE-2022-27925

HIGH KEV RANSOMWARE

Zip Path Traversal in Zimbra (mboximport) (CVE-2022-27925)

Title source: metasploit
STIX 2.1

Exploitation Summary

CVE-2022-27925 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added August 11, 2022, with confirmed use in ransomware campaigns. EIP tracks 12 public exploits from researchers including vnhacker1337, Josexv1, SystemVll.

AI-analyzed exploit summary This PoC exploits CVE-2022-27925, a Zimbra RCE vulnerability, by uploading malicious ZIP files to trigger command execution. It checks for a successful shell by verifying the presence of a JSP webshell.

Description

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.

Exploits (12)

nomisec WORKING POC 66 stars
by vnhacker1337 · remote
https://github.com/vnhacker1337/CVE-2022-27925-PoC

This PoC exploits CVE-2022-27925, a Zimbra RCE vulnerability, by uploading malicious ZIP files to trigger command execution. It checks for a successful shell by verifying the presence of a JSP webshell.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Zimbra Collaboration Suite (versions affected by CVE-2022-27925)
Auth required
Prerequisites: Valid Zimbra account credentials · Network access to the Zimbra server · Pre-generated malicious ZIP files (312.zip, 313.zip, 314.zip)
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 43 stars
by Josexv1 · remote
https://github.com/Josexv1/CVE-2022-27925

This repository contains a functional exploit for CVE-2022-27925, a path traversal vulnerability in Zimbra Collaboration Suite Network Edition. The exploit leverages an authentication bypass (CVE-2022-37042) to deploy a JSP webshell, achieving remote code execution as the Zimbra user.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Zimbra Collaboration Suite Network Edition (9.0.0 Patch 23 and earlier, 8.8.15 Patch 30 and earlier)
No auth needed
Prerequisites: Network access to the Zimbra administrator port (default: 7071) · Vulnerable Zimbra Collaboration Suite Network Edition instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 18 stars
by SystemVll · remote
https://github.com/SystemVll/CVE-2022-27925

This is a functional exploit for CVE-2022-27925, targeting Zimbra Collaboration Suite. It leverages a path traversal vulnerability to upload a malicious JSP file, achieving remote code execution (RCE) via a crafted ZIP archive.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Zimbra Collaboration Suite Network Edition 9.0.0 Patch 23 (and earlier), 8.8.15 Patch 30 (and earlier)
No auth needed
Prerequisites: Target must be running a vulnerable version of Zimbra · Network access to the Zimbra web interface
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP 8 stars
by jam620 · poc
https://github.com/jam620/Zimbra

This repository provides a detailed writeup and analysis of CVE-2022-27925, an unauthenticated RCE vulnerability in Zimbra Collaboration Server. It includes steps for enumeration, exploitation, and post-exploitation analysis, along with references to APT activities and malware found in compromised systems.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Zimbra Collaboration Server (ZCS)
No auth needed
Prerequisites: Shodan API access · Docker · jq · Python3 · VPS (preferably Ubuntu Server 20.04)
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 4 stars
by Chocapikk · remote
https://github.com/Chocapikk/CVE-2022-27925-Revshell

This repository contains a functional exploit for CVE-2022-27925, an unauthenticated remote code execution vulnerability in Zimbra. The exploit uploads a malicious ZIP file containing JSP webshells and reverse shells to vulnerable endpoints, leveraging path traversal to achieve execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Zimbra Collaboration Suite (versions affected by CVE-2022-27925)
No auth needed
Prerequisites: Network access to the target Zimbra instance · Vulnerable Zimbra version exposed to the internet
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec STUB 3 stars
by akincibor · remote
https://github.com/akincibor/CVE-2022-27925

The repository contains only a README.md file mentioning a Nuclei template for CVE-2022-27925, but no actual exploit code or template is provided. It appears to be a placeholder or incomplete submission.

Classification
Stub 30%
Attack Type
Other
Complexity
Theoretical
Reliability
Theoretical
Target: unknown (likely Zimbra Collaboration Suite based on CVE-2022-27925)
No auth needed
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 1 stars
by touchmycrazyredhat · remote
https://github.com/touchmycrazyredhat/CVE-2022-27925-Revshell

This is a functional exploit for CVE-2022-27925, targeting Zimbra Collaboration Suite. It achieves unauthenticated remote code execution by uploading a malicious ZIP file containing JSP webshells and reverse shells via the mboximport endpoint.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Zimbra Collaboration Suite (versions affected by CVE-2022-27925)
No auth needed
Prerequisites: Network access to the target Zimbra instance · Target must be vulnerable to CVE-2022-27925
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by sanan2004 · remote
https://github.com/sanan2004/CVE-2022-27925

This repository contains a working proof-of-concept exploit for CVE-2022-27925, a path-traversal vulnerability in Zimbra Collaboration Suite Network Edition. The exploit leverages an authentication bypass (CVE-2022-37042) to achieve unauthenticated remote code execution by uploading a malicious ZIP file to deploy a JSP webshell.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Zimbra Collaboration Suite Network Edition 9.0.0 Patch 23 (and earlier), 8.8.15 Patch 30 (and earlier)
No auth needed
Prerequisites: Access to the Zimbra administrator port (default: 7071) · Vulnerable version of Zimbra Collaboration Suite Network Edition
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by onlyHerold22 · remote
https://github.com/onlyHerold22/CVE-2022-27925-PoC

This PoC exploits CVE-2022-27925, a Zimbra Collaboration Suite vulnerability allowing unauthenticated remote code execution via crafted ZIP uploads to the mboximport endpoint. The script automates the exploit by sending malicious ZIP payloads and checking for a successful shell.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Zimbra Collaboration Suite (versions affected by CVE-2022-27925)
No auth needed
Prerequisites: Network access to Zimbra admin interface · Valid email account on the target system
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by navokus · poc
https://github.com/navokus/CVE-2022-27925

This PoC exploits CVE-2022-27925, a path traversal vulnerability in Zimbra Collaboration Suite, to upload a malicious JSP shell. The exploit crafts a ZIP file containing the shell and sends it via HTTP POST requests to vulnerable endpoints, then triggers the shell via a GET request.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0
No auth needed
Prerequisites: Network access to the Zimbra server · Vulnerable version of Zimbra Collaboration Suite
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by miko550 · poc
https://github.com/miko550/CVE-2022-27925

This is a Python-based exploit for CVE-2022-27925, an unauthenticated remote code execution vulnerability in Zimbra. The script uploads malicious ZIP files to trigger command execution and checks for a successful shell at a predefined path.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Zimbra Collaboration Suite (versions affected by CVE-2022-27925)
No auth needed
Prerequisites: Network access to the target Zimbra instance · Zimbra instance vulnerable to CVE-2022-27925
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by huahuatzt · poc
https://github.com/huahuatzt/CVE-2022-27925

This is a functional exploit for CVE-2022-27925, targeting Zimbra Collaboration Suite. It achieves unauthenticated remote code execution by uploading a malicious ZIP file containing a JSP webshell, then interacting with it to execute arbitrary commands.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Zimbra Collaboration Suite (versions affected by CVE-2022-27925)
No auth needed
Prerequisites: Network access to the Zimbra web interface · Vulnerable Zimbra instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Vendor Advisory x_refsource_misc
https://wiki.zimbra.com/wiki/Security_Center
Release Notes, Vendor Advisory x_refsource_misc
https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P24
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/168146/Zimbra-Zip-Path-Traversal.html

Scores

CVSS v3 7.2
EPSS 0.9431
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2022-08-11
VulnCheck KEV 2022-08-11
InTheWild.io 2022-08-11
ENISA EUVD EUVD-2022-32413
Ransomware Use Confirmed
CWE
CWE-22
Status published
Products (2)
synacor/zimbra_collaboration_suite 8.8.15 (31 CPE variants)
synacor/zimbra_collaboration_suite 9.0.0 (19 CPE variants)
Published Apr 21, 2022
KEV Added Aug 11, 2022
Tracked Since Feb 18, 2026