Vulnerabilities - CISA Adds SharePoint and Zimbra Flaws
Basically, CISA found serious flaws in SharePoint and Zimbra that could let hackers run harmful code.
CISA has added critical vulnerabilities in Microsoft SharePoint and Zimbra to its catalog. These flaws could allow attackers to execute code remotely, posing serious risks. Organizations must act quickly to patch these vulnerabilities and safeguard their systems.
The Flaw
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently added two significant vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. The first, CVE-2026-20963, affects Microsoft SharePoint. This vulnerability involves a deserialization of untrusted data, which allows an attacker to execute arbitrary code on the SharePoint server over a network. The second vulnerability, CVE-2025-66376, is a stored Cross-Site Scripting (XSS) flaw in the Zimbra Collaboration Suite (ZCS). This flaw allows attackers to exploit CSS @import directives in email HTML, potentially compromising user data.
What's at Risk
Both vulnerabilities pose a high risk to organizations using these platforms. The SharePoint flaw, with a CVSS score of 8.8, indicates a critical level of severity. An unauthenticated attacker could leverage this vulnerability to inject and execute malicious code remotely. The Zimbra flaw, rated at 7.2, also presents a significant risk, as it can be exploited to execute harmful scripts in the context of the user's session. Given the widespread use of these applications, the potential impact on data integrity and security is considerable.
Patch Status
CISA has mandated that federal agencies address these vulnerabilities promptly. The deadline for fixing the SharePoint vulnerability is set for March 21, 2026, while the Zimbra flaw must be resolved by April 1, 2026. Organizations are urged to review the KEV catalog and take immediate action to patch these vulnerabilities in their systems. This proactive approach is crucial in safeguarding against potential exploitation.
Immediate Actions
To mitigate the risks associated with these vulnerabilities, organizations should take the following steps:
- Update Systems: Ensure that all instances of SharePoint and Zimbra are updated with the latest security patches.
- Monitor for Exploits: Keep an eye on network traffic for any signs of exploitation attempts related to these vulnerabilities.
- Educate Staff: Inform employees about the potential risks and encourage them to report any suspicious activity.
By taking these actions, organizations can better protect their networks and data from potential attacks stemming from these newly identified vulnerabilities.
Security Affairs