Exploited in the Wild: CISA Warns of Active Attacks on Microsoft SharePoint and Zimbra
ID: 5251b269-cacf-5084-8f29-19ef69ea304c
STIX ID: report--5251b269-cacf-5084-8f29-19ef69ea304c
Feed Name: securityonline.info
CISA added two actively exploited flaws to its KEV catalog: CVE-2026-20963, a critical deserialization-based remote code execution in Microsoft SharePoint (CVSS 9.8) that allows unauthenticated remote code execution and is being used against unpatched servers, and CVE-2025-66376, a stored CSS/@import-based XSS in Synacor Zimbra Collaboration Suite affecting specific 10.x versions via crafted emails; CISA inclusion signals active exploitation and the need for immediate patching across federal and private environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
