CISA KEV · catalog date May 19, 2025 · first observed Jul 19, 2026
Evidence dossier
CVE-2024-27443
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0.
Exploited in the wild (CISA KEV since May 19, 2025). NVD reports CVSS 3.1 6.1. EPSS estimates 23.6% exploit likelihood as of Aug 27, 2026.
As of Aug 27, 2026
Normalized restatement
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail classic user interface, because of improper input validation in the handling of the calendar header. An attacker can exploit this via an email message containing a crafted calendar header with an embedded XSS payload. When a victim views this message in the Zimbra webmail classic interface, the payload is executed in the context of the victim's session, potentially leading to execution of arbitrary JavaScript code.
- State
- PUBLISHED
- Published
- Aug 12, 2024
- Updated
- Oct 21, 2025
- Evidence coverage
- 99%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCAmitreOriginal evidence ↗
Record text: An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail classic user interface, because of improper input validation in the handling of the calendar header. An attacker can exploit this via an email message containing a crafted calendar header with an embedded XSS payload. When a victim views this message in the Zimbra webmail classic interface, the payload is executed in the context of the victim's session, potentially leading to execution of arbitrary JavaScript code.
Inspect raw assertion
- Field
container- Value
- An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail classic user interface, because of improper input validation in the handling of the calendar header. An attacker can exploit this via an email message containing a crafted calendar header with an embedded XSS payload. When a victim views this message in the Zimbra webmail classic interface, the payload is executed in the context of the victim's session, potentially leading to execution of arbitrary JavaScript code.
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 23.63% probability · 97.64th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.236320000000; percentile 0.976350000000
FIRST EPSS · score date Aug 27, 2026 · 97.6th percentile · first observed Aug 27, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
Outside this view’s verified evidenceReason detail begins outside this selected snapshot; the state remains source-bound.
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail classic user interface, because of improper input validation in the handling of the calendar header. An attacker can exploit this via an email message containing a crafted calendar header with an embedded XSS payload. When a victim views this message in the Zimbra webmail classic interface, the payload is executed in the context of the victim's session, potentially leading to execution of arbitrary JavaScript code.
Inspect raw assertion
- Field
container- Value
- An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail classic user interface, because of improper input validation in the handling of the calendar header. An attacker can exploit this via an email message containing a crafted calendar header with an embedded XSS payload. When a victim views this message in the Zimbra webmail classic interface, the payload is executed in the context of the victim's session, potentially leading to execution of arbitrary JavaScript code.
Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
23.63% probability · 97.64th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.236320000000; percentile 0.976350000000
Applicability
Cited product scope
Grouped from 1 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
2 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "n/a"}]product-c9dd24e598ea6efd6f621419944d8fa9d1d276a86d677edd361ec9d03da31d7bLinked exactInspect raw assertions
cpe:2.3:a:zimbra:collaboration:9.0.0:p11:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4bb93336-cc3c-4b7f-b194-7ded036abbaf
cpe:2.3:a:zimbra:collaboration:9.0.0:p1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
bde59185-b917-4a81-8de4-c65a079f52fe
cpe:2.3:a:zimbra:collaboration:9.0.0:p25:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 18
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
bc19f11d-23d9-429d-a957-d67f23a40a01
cpe:2.3:a:zimbra:collaboration:9.0.0:p14:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f9ea2a61-67aa-4b7e-bc6e-80eb1363ef85
cpe:2.3:a:zimbra:collaboration:9.0.0:p6:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 33
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4b52d301-2559-457a-8ffb-f0915299355a
cpe:2.3:a:zimbra:collaboration:9.0.0:p21:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 14
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9503131f-cc23-4545-ae9c-9714b287cc25
cpe:2.3:a:zimbra:collaboration:9.0.0:p33:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 25
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d659ae6a-591e-4d5b-9781-9648250f5576
cpe:2.3:a:zimbra:collaboration:9.0.0:p34:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 26
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e4054e3e-561c-4b1c-a615-3cce5cb69d77
cpe:2.3:a:zimbra:collaboration:9.0.0:p26:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 19
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
aafa2ee7-c965-4f27-8cae-e607a9f202ad
cpe:2.3:a:zimbra:collaboration:9.0.0:p32:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 24
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9679fd62-815e-47a8-8552-d28ce48b82b2
cpe:2.3:a:zimbra:collaboration:9.0.0:p38:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 30
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
32a352c4-0e9c-436f-ada7-d93492a18037
cpe:2.3:a:zimbra:collaboration:9.0.0:p0:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5e4df01a-1aa9-47e8-82fd-65a02eca1376
cpe:2.3:a:zimbra:collaboration:9.0.0:p35:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 27
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4fa0e9c4-25e4-4cd6-b88a-02b413385866
cpe:2.3:a:zimbra:collaboration:9.0.0:p36:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 28
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5d6f7ca3-c36a-466c-8fad-d0b3cef01f0e
cpe:2.3:a:zimbra:collaboration:9.0.0:p5:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 32
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
82000ba4-1781-4312-a7bd-92ec94d137ae
cpe:2.3:a:zimbra:collaboration:9.0.0:p7.1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 35
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8d859f77-8e39-4d46-bc90-c5c1d805a666
cpe:2.3:a:zimbra:collaboration:9.0.0:p24:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 16
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8113a4e3-aa96-4382-815d-6fd88ba42ec5
cpe:2.3:a:zimbra:collaboration:9.0.0:p20:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 13
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
40629beb-df4b-4fb8-8d3d-7bac43c90766
cpe:2.3:a:zimbra:collaboration:9.0.0:p24.1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 17
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
dc8c28e0-6c51-41ee-a7b2-db185d1d8fd0
cpe:2.3:a:zimbra:collaboration:9.0.0:p8:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 36
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
cdc810c7-45da-4bdf-9138-2d3b2750243e
cpe:2.3:a:zimbra:collaboration:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 10.0.0; through excluding 10.0.7
- Match ID
4ce0029a-44ea-4774-879d-5fa2d35f09bd
cpe:2.3:a:zimbra:collaboration:9.0.0:p15:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c77a35b7-96f6-43a7-a747-c6aeede961e1
cpe:2.3:a:zimbra:collaboration:9.0.0:p12:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
876f1675-f65c-4e86-adbd-36eb8d8a997d
cpe:2.3:a:zimbra:collaboration:9.0.0:p30:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 22
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
fd1dce2b-d944-43ae-ad0e-9282de6d618f
cpe:2.3:a:zimbra:collaboration:9.0.0:p4:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 31
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
33f50d8c-7027-4a8d-8e95-98c224283772
cpe:2.3:a:zimbra:collaboration:9.0.0:p7:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 34
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7215ae2c-8a33-4ab9-88d5-7c8cd11e806c
cpe:2.3:a:zimbra:collaboration:9.0.0:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
685d9652-2934-4c13-8b36-40582c79bfc1
cpe:2.3:a:zimbra:collaboration:9.0.0:p27:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 20
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1d09dcf6-1c8f-4ca1-b7d4-afdd4eb35771
cpe:2.3:a:zimbra:collaboration:9.0.0:p31:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 23
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2079b9f8-128b-487d-a965-e8b37fdf6304
cpe:2.3:a:zimbra:collaboration:9.0.0:p16:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
dc35882b-e709-42d8-8800-f1b734ceafc3
cpe:2.3:a:zimbra:collaboration:9.0.0:p37:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 29
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9684ac81-b557-4292-8402-ae55cb2e613c
cpe:2.3:a:zimbra:collaboration:9.0.0:p3:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 21
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c52705e6-2c6b-47bc-a0cd-f6aae0bfc302
cpe:2.3:a:zimbra:collaboration:9.0.0:p10:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ba3ed95f-95f2-4676-8eaf-b4b9eb64b260
cpe:2.3:a:zimbra:collaboration:9.0.0:p9:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 37
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e09d95a4-764d-4e0b-8605-1d94fd548ab2
cpe:2.3:a:zimbra:collaboration:9.0.0:p13:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2306f526-9c56-4a57-aa9b-02f2d6058c97
cpe:2.3:a:zimbra:collaboration:9.0.0:p19:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 11
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b7a47276-f241-4a68-9458-e1481ebdc5e6
cpe:2.3:a:zimbra:collaboration:9.0.0:p23:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 15
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b4ce2d12-ad31-4fed-ad0f-adf64e92e1b1
cpe:2.3:a:zimbra:collaboration:9.0.0:p2:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 12
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
12d0d469-6c9b-4b66-9581-dc319773238a
Affected-product evidence
Accepted scope and product mapping
0 canonical links · 0 source-reported links
Applicability remains source-scoped; safety and exposure remain unassessed.
Assessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NEvidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Affected-product evidence remains source-scoped; canonical linkage is required before applicability scoring.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.