Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-68645

90
FAUCET Score

CVE-2025-68645 is a critical Local File Inclusion (LFI) vulnerability found in the Webmail Classic UI of Zimbra Collaboration (ZCS) versions 10.0 and 10.1. This flaw allows an unauthenticated remote attacker to craft requests to the /h/rest endpoint, leveraging improper parameter handling to include arbitrary files from the WebRoot directory. With a CVSS score of 8.8 (HIGH), it poses a significant risk to confidentiality, integrity, and availability due to its low attack complexity and lack of authentication requirement. The vulnerability is actively exploited in the wild, confirmed by its inclusion in CISA's KEV catalog and extensive community discussion, with Nuclei templates publicly available.

Impacted Technologies

VendorProductVersion(s)CPE
>= 10.0.0, < 10.0.18CPE matchmatch criteria
cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*
>= 10.1.0, < 10.1.13CPE matchmatch criteria
cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
31.77%
Probability of exploitation in next 30 days
EPSS Percentile
98.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
Added to KEV · Jan 22, 2026
Nuclei: CVE-2025-68645 · Dec 31, 2025
This CVE's current EPSS score of 0.3177 is in the 99th percentile among its peer group of 14,825 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Vendor Patches (4)

3cxvendor investigatingvia llm_extracted
horillavendor investigatingvia llm_extracted
inveniosoftwarevendor investigatingvia llm_extracted
jitsivendor investigatingvia llm_extracted

Vendor Advisories (5)

horillallm-horilla-ffa7ad9f787b8c87HIGH

Zimbra Collaboration Suite Local File Inclusion (CVE-2025-68645)

Jan 1, 2026
inveniosoftwarellm-inveniosoftware-91bc6703f192f005HIGH

Zimbra Collaboration Suite Local File Inclusion (CVE-2025-68645)

Jan 1, 2026
jitsillm-jitsi-9552c8b1480888ceHIGH

Zimbra Collaboration Suite Local File Inclusion (CVE-2025-68645)

Jan 1, 2026
jitsillm-jitsi-936213be36481d98HIGH

Zimbra Collaboration Local File Inclusion (CVE-2025-68645)

Jan 1, 2026
3cxllm-3cx-a55d31ccc54c2f6cHIGH

Zimbra Collaboration Suite Local File Inclusion (CVE-2025-68645)

Jan 1, 2026

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
wiki.zimbra.com / wiki/Security_Center
Release NotesVendor Advisory
wiki.zimbra.com / wiki/Zimbra_Responsible_Disclosure_Policy
Product