Visualização normal

Ontem — 7 de Setembro de 2026Stream principal
  • ✇Cybersecurity News
  • Roundcube Security Update Fixes 12 Webmail Flaws Do Son
    The Roundcube security update fixes 12 webmail flaws, including a zero-click stored XSS and an SSRF bypass. Update to 1.6.19 or 1.7.4 now. Related Posts: CVE-2026-86218 (CVSS 10): N-central Pre-Auth RCE Exploited in the Wild MikroTrick PoC: RouterOS Admin Rights Exploited In Wild AI Agent Coordination: The Unprecedented OpenAI Breakout The post Roundcube Security Update Fixes 12 Webmail Flaws appeared first on Daily CyberSecurity.
     
Antes de ontemStream principal
  • ✇Cybersecurity News
  • CVE-2026-21580: Stored XSS Hits Atlassian Confluence Do Son
    A Confluence vulnerability, CVE-2026-21580, is a stored XSS flaw (CVSS 8.6) allowing unauthenticated attacks. A Jira flaw also patched. Update now. Related Posts: CVE-2026-13737: Commvault Command Execution Flaws Expose Networks CVE-2026-18051 (CVSS 10): Unauthenticated Arbitrary File Write Hits 900k W3 Total Cache Sites BeyondTrust EPM Flaws Allow Windows Privilege Escalation The post CVE-2026-21580: Stored XSS Hits Atlassian Confluence appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Roundcube Patches RCE and SSRF Flaws in 1.6.18 and 1.7.3 Do Son
    Roundcube fixes a webmail RCE flaw and an SSRF filter bypass in versions 1.6.18 and 1.7.3. Update your mail server now. Related Posts: CVE-2026-19188: Haiwell HMI Gateway Flaw Lets Attackers Execute Arbitrary OS Commands With Root Privileges (CVSS 10.0) Linux AF_PACKET Race (03390aa): PoC Exploit Enables Local Privilege Escalation Citrix NetScaler Pre-Auth RCE CVE-2026-8452 Gets Public Exploit Code The post Roundcube Patches RCE and SSRF Flaws in 1.6.18 and 1.7.3 appeared first on Daily Cyber
     
  • ✇Cybersecurity News
  • GitLab Patch Release Fixes 13 Flaws, Including High-Severity XSS Bugs Do Son
    The new GitLab patch release fixes 13 flaws, including high-severity XSS and authorization bugs. Update to 19.2.2, 19.1.4, or 19.0.6 now. Related Posts: Zero-Click File Drop Hits Xiaomi ShareMe: PoC Public CVE-2026-65640: WordPress 7.0.4 Fixes Remote Code Execution MariaDB Low-Privilege Remote Code Execution Chain: Full Details and PoC Exploit Code Publicly Disclosed The post GitLab Patch Release Fixes 13 Flaws, Including High-Severity XSS Bugs appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • BdThemes Supply Chain Attack Poisons Plugin API to Hijack WordPress Admins Do Son
    A BdThemes supply chain attack poisoned a plugin API feed to run silent XSS in admin browsers, creating rogue admins across WordPress sites. Related Posts: Fake AI Tools Malware Targets Developers Through GitHub DOUBLECUP: New ClickFix Loader Drops CountLoader and DeviceManager RAT Interlock Ransomware Abuses Volatility3 for Credential Theft The post BdThemes Supply Chain Attack Poisons Plugin API to Hijack WordPress Admins appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • CVE-2026-64638: WordPress Pre-Auth XSS Flaw Can Escalate to Remote Code Execution Do Son
    WordPress 7.0.3 fixes CVE-2026-64638, a pre-auth XSS on the login screen that can escalate to remote code execution. CVSS 8.9. Update now. Related Posts: Metabase SQL Injection Zero-Day (CVSS 10) Exploited Multiple ClamAV Flaws Let Remote Attackers Cause DoS CryptoJS Randomness Vulnerability Drains Crypto Wallets The post CVE-2026-64638: WordPress Pre-Auth XSS Flaw Can Escalate to Remote Code Execution appeared first on Daily CyberSecurity.
     
  • ✇Security Affairs
  • Update Now: Critical Zimbra Classic Web Client Flaw Could Expose Mailboxes Pierluigi Paganini
    Zimbra addressed a critical stored XSS vulnerability in its Classic Web Client that lets malicious emails execute code when opened. Zimbra has released version 10.1.19 to fix a critical stored XSS vulnerability in its Classic Web Client, which is widely used to access Zimbra Collaboration. The flaw, which has not yet received a CVE ID, can be exploited by sending specially crafted emails that execute malicious code when opened in the Classic UI.  Successful exploitation could allow attackers
     

Update Now: Critical Zimbra Classic Web Client Flaw Could Expose Mailboxes

10 de Julho de 2026, 17:42

Zimbra addressed a critical stored XSS vulnerability in its Classic Web Client that lets malicious emails execute code when opened.

Zimbra has released version 10.1.19 to fix a critical stored XSS vulnerability in its Classic Web Client, which is widely used to access Zimbra Collaboration. The flaw, which has not yet received a CVE ID, can be exploited by sending specially crafted emails that execute malicious code when opened in the Classic UI.  Successful exploitation could allow attackers to access to mailbox information, session data, or account settings.

“The update fixes a security issue in the Classic Web Client where a specially crafted email could run malicious code when the email is opened. If exploited, it could allow access to mailbox information, session data, or account settings.” reads the advisory

“We strongly recommend all customers to upgrade to ZCS v10.1.19 to ensure they have received the latest security patches, bug fixes, and enhancements.”

Google’s Threat Analysis Group discovered the vulnerability.

Although there is no evidence of active exploitation yet, organizations using the Classic Web Client should update as soon as possible.

Since the beginning of 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added [1, 2, 3] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog:

  • CVE-2025-68645 (CVSS score of 8.8) Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability
  • CVE-2020-7796 (CVSS score of 9.8) Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability
  • CVE-2025-66376 (CVSS score of 7.2) Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability.

In March, Russia-linked APT group, likely APT28  (aka UAC-0001, aka Fancy BearPawn StormSofacy GroupSednit, BlueDelta, and STRONTIUM), exploited the vulnerability CVE-2025-66376 in attacks against entities in Ukraine. Attackers used JavaScript in phishing emails to silently harvest credentials, session tokens, 2FA codes, saved passwords, and 90 days of mailbox data. Then they exfiltrated stolen data via DNS and HTTPS.

A national maritime agency was targeted on January 22 using a compromised student email. Seqrite Labs tracked this campaign as Operation GhostMail.

A phishing email targeted Ukraine’s State Hydrology Agency, part of critical infrastructure, using a compromised student account to appear legitimate. The message hid malicious JavaScript in the HTML body, exploiting a Zimbra XSS flaw (CVE-2025-66376).

Once opened, it executed in the user’s session, stealing credentials, tokens, emails, and 2FA data. The multi-stage payload used SOAP requests, DNS and HTTPS exfiltration, and enabled persistent access, allowing attackers to monitor accounts and extract up to 90 days of emails.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, XSS)

Zero-Click pretalx XSS Flaw Lets Hackers Hijack Conference Organizer Accounts

pretalx XSS flaw lets attackers hijack conference organizer accounts, steal sessions, auto-accept talks, and demote admins. Patched in v2026.1.0.
❌
❌