Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 01 Apr 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Synacor
Synacor zimbra Collaboration Suite |
|
| CPEs | cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Synacor
Synacor zimbra Collaboration Suite |
Wed, 25 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | XML External Entity Vulnerability in Zimbra Collaboration 10.0/10.1 EWS SOAP Interface |
Mon, 23 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-611 | |
| Metrics |
cvssV3_1
|
Fri, 20 Mar 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zimbra
Zimbra collaboration |
|
| Vendors & Products |
Zimbra
Zimbra collaboration |
Fri, 20 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. An XML External Entity (XXE) vulnerability exists in the Zimbra Exchange Web Services (EWS) SOAP interface due to improper handling of XML input. An authenticated attacker can submit crafted XML data that is processed by an XML parser with external entity resolution enabled. Successful exploitation may allow disclosure of sensitive local files from the server. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-03-23T13:39:46.789Z
Reserved: 2026-03-19T00:00:00.000Z
Link: CVE-2026-33371
Updated: 2026-03-23T13:39:10.282Z
Status : Analyzed
Published: 2026-03-20T14:16:16.240
Modified: 2026-04-01T15:35:47.497
Link: CVE-2026-33371
No data.
OpenCVE Enrichment
Updated: 2026-03-25T14:10:24Z