logo

U.S. CISA adds Microsoft SharePoint and Zimbra  flaws to its Known Exploited Vulnerabilities catalog

ID: 78db5acb-097e-5a1f-ac1e-9de5fa0fc107

STIX ID: report--78db5acb-097e-5a1f-ac1e-9de5fa0fc107

Feed Name: Security Affairs

Threat Score
70/100

Date Published: 2026-03-18

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

CISA has added Microsoft SharePoint CVE-2026-20963 (deserialization of untrusted data enabling remote code execution; CVSS 8.8) and Synacor Zimbra CVE-2025-66376 (stored XSS in Classic UI; CVSS 7.2) to its Known Exploited Vulnerabilities catalog, and ordered federal agencies to remediate by March 21, 2026 and April 1, 2026 respectively, urging private organizations to address these issues as well.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.