CVE-2025-71275: Zimbra Collaboration Suite PostJournal 8.8.15 Unauthenticated Remote Code Execution via SMTP Injection
Published Mar 24, 2026
·Updated
Rejected reason: This CVE was rejected due to being a duplicate of CVE-2024-45519.
Affected Software
1 affected component
Zimbra Zimbra Collaboration Suite PostJournal=8.8.15
Event History
Mar 24, 2026
CVE Published
via MITRE·03:21 PM
Rejected
via MITRE·03:21 PM
Data Sourced
via NVD·04:16 PM
Description
Mar 25, 2026
Rejected
via MITRE·03:39 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-71275?
CVE-2025-71275 is considered a critical vulnerability due to its ability to allow unauthenticated remote code execution.
2
How do I fix CVE-2025-71275?
To mitigate CVE-2025-71275, upgrade to a patched version of Zimbra Collaboration Suite PostJournal that resolves this vulnerability.
3
What is the exploit mechanism for CVE-2025-71275?
CVE-2025-71275 exploits SMTP injection to allow unauthorized attackers to execute arbitrary system commands.
4
Who is affected by CVE-2025-71275?
CVE-2025-71275 affects users running Zimbra Collaboration Suite PostJournal version 8.8.15.
5
What are the potential impacts of CVE-2025-71275?
The potential impacts of CVE-2025-71275 include full system compromise and unauthorized control over affected systems.