Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

DarkSword iOS exploit kit uses 6 flaws, 3 zero-days to take over entire device

Muon detector network for monitoring space and terrestrial weather

How agrivoltaics can accelerate Europe’s energy transition

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Warning of CISA, Zimbra, SharePoint flaw exploitation. Cisco’s zero-day hit in ransomware attacks
Identity

Warning of CISA, Zimbra, SharePoint flaw exploitation. Cisco’s zero-day hit in ransomware attacks

By March 19, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ravi LakshmananMarch 19, 2026Network security/vulnerabilities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has urged government agencies to patch two security flaws affecting Synacor Zimbra Collaboration Suite (ZCS) and Microsoft Office SharePoint, saying they are actively being exploited in the wild.

The vulnerabilities in question are:

CVE-2025-66376 (CVSS Score: 7.2) – A stored cross-site scripting vulnerability in the classic UI of ZCS allows an attacker to exploit Cascading Style Sheets (CSS) @import directives in HTML email messages. (Fixed in November 2025 in versions 10.0.18 and 10.1.13) CVE-2026-20963 (CVSS Score: 8.8) – Deserialization of Untrusted Data Vulnerability in Microsoft Office SharePoint allows an unprivileged attacker to execute code via the network. (revised January 2026)

At this time, there are no public reports addressing the exploitation of the aforementioned flaw, who is exploiting it, or its scale. In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies are encouraged to apply the patch for CVE-2025-66376 by April 1, 2026 and the patch for CVE-2026-20963 by March 23, 2026.

This disclosure comes after Amazon revealed that attackers associated with the Interlock ransomware had been exploiting a maximum severity security flaw (CVE-2026-20131, CVSS score: 10.0) affecting Cisco’s firewall management software since January 26, 2026, more than a month before it was made publicly available.

“Interlock has historically targeted specific sectors where operational disruptions would put the greatest pressure on payments,” Amazon said. These sectors include education, engineering, architecture, construction, manufacturing, industry, healthcare, and government.

This attack once again highlights a persistent pattern of attackers targeting edge network devices from a variety of vendors, including Cisco, Fortinet, and Ivanti, to gain initial access to target networks. The fact that CVE-2026-20131 was weaponized as a zero-day indicates that attackers are investing time and resources to find previously unknown flaws that could allow elevated access.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleNothing CEO Karl Pei says smartphone apps will disappear if they are replaced by AI agents
Next Article From materials to real power

Related Posts

DarkSword iOS exploit kit uses 6 flaws, 3 zero-days to take over entire device

March 19, 2026

OFAC sanctions North Korean IT worker network for funding weapons of mass destruction program through fake remote jobs

March 18, 2026

Interlock ransomware exploits Cisco FMC Zero-Day CVE-2026-20131 to gain root access

March 18, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

DarkSword iOS exploit kit uses 6 flaws, 3 zero-days to take over entire device

Muon detector network for monitoring space and terrestrial weather

How agrivoltaics can accelerate Europe’s energy transition

From materials to real power

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.