By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: CISA Warns of Zimbra, SharePoint Flaw Exploits; Cisco Zero-Day Hit in Ransomware Attacks
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > CISA Warns of Zimbra, SharePoint Flaw Exploits; Cisco Zero-Day Hit in Ransomware Attacks
Computing

CISA Warns of Zimbra, SharePoint Flaw Exploits; Cisco Zero-Day Hit in Ransomware Attacks

News Room
Last updated: 2026/03/19 at 2:40 AM
News Room Published 19 March 2026
Share
CISA Warns of Zimbra, SharePoint Flaw Exploits; Cisco Zero-Day Hit in Ransomware Attacks
SHARE

Ravie LakshmananMar 19, 2026Network Security / Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has urged government agencies to apply patches for two security flaws impacting Synacor Zimbra Collaboration Suite (ZCS) and Microsoft Office SharePoint, stating they have been actively exploited in the wild.

The vulnerabilities in question are as follows –

  • CVE-2025-66376 (CVSS score: 7.2) – A stored cross-site scripting vulnerability in the Classic UI of ZCS, where attackers could abuse Cascading Style Sheets (CSS) @import directives in an HTML e-mail message. (Fixed in versions 10.0.18 and 10.1.13 in November 2025)
  • CVE-2026-20963 (CVSS score: 8.8) – A deserialization of untrusted data vulnerability in Microsoft Office SharePoint that allows an unauthorized attacker to execute code over a network. (Fixed in January 2026)

There are currently no public reports referencing the exploitation of aforementioned flaws, who may be exploiting them, and the scale of such efforts. In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies are recommended to apply patches for CVE-2025-66376 by April 1, 2026, and for CVE-2026-20963 by March 23, 2026.

The disclosure comes as Amazon revealed that threat actors associated with Interlock ransomware have exploited a maximum-severity security flaw impacting Cisco’s firewall management software (CVE-2026-20131, CVSS score: 10.0) since January 26, 2026, more than a month before it was publicly disclosed.

“Interlock has historically targeted specific sectors where operational disruption creates maximum pressure for payment,” Amazon said. These sectors include education, engineering, architecture, construction, manufacturing, industrial, health care, and government entities.

The attack once again highlights a persistent pattern of threat actors targeting edge network devices from different vendors, including Cisco, Fortinet, Ivanti, and others, to obtain initial access to target networks. The fact that CVE-2026-20131 was weaponized as a zero-day shows that attackers are investing time and resources to find previously unknown flaws that could grant them elevated access.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article It’s Time to Stop Using Face ID. Here’s Why It’s Time to Stop Using Face ID. Here’s Why
Next Article Apple TV: Grey’s Anatomy alum joins The Morning Show’s season 5 – 9to5Mac Apple TV: Grey’s Anatomy alum joins The Morning Show’s season 5 – 9to5Mac
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Firefox 151 lets you choose VPN location and boosts its AI on mobile
Firefox 151 lets you choose VPN location and boosts its AI on mobile
Mobile
iX workshop IT security: methodically plan, request and analyze pentests
iX workshop IT security: methodically plan, request and analyze pentests
Software
Arxiv bans researchers who submit AI slop
Arxiv bans researchers who submit AI slop
News
What it is, what Google Video Creation AI offers and how to use it
What it is, what Google Video Creation AI offers and how to use it
Gaming

You Might also Like

already good for the trash after 350 hours?
Computing

already good for the trash after 350 hours?

5 Min Read
Orange’s Wi-Fi 7 repeater is finally here, and it doesn’t come alone!
Computing

Orange’s Wi-Fi 7 repeater is finally here, and it doesn’t come alone!

4 Min Read
Sucker Punch already stops costs on Ghost of Yotei: Legends
Computing

Sucker Punch already stops costs on Ghost of Yotei: Legends

4 Min Read
OpenAI now has its hands free!
Computing

OpenAI now has its hands free!

5 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?