Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.
https://thehackernews.com/2026/08/uat-10147-uses-ai-to-scale-server.html
https://thehackernews.com/2026/06/new-sharkloader-malware-deploys-cobalt.html
https://securelist.com/strikeshark-campaign/120326/
https://www.greynoise.io/blog/unmasking-cisas-hidden-kev-ransomware-updates
https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-207a
https://www.tenable.com/cyber-exposure/tenable-2022-threat-landscape-report
https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-228a
https://github.com/romero-javi/zimbra8_lab
https://github.com/0xf4n9x/CVE-2022-37042
https://github.com/jam620/Zimbra
https://github.com/lolminerxmrig/CVE-2022-27925-Revshell
https://github.com/akincibor/CVE-2022-27925
https://github.com/Chocapikk/CVE-2022-27925-Revshell
https://github.com/Josexv1/CVE-2022-27925
https://github.com/mohamedbenchikh/CVE-2022-27925
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-27925
https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P24
https://wiki.zimbra.com/wiki/Security_Center
http://packetstormsecurity.com/files/168146/Zimbra-Zip-Path-Traversal.html