Wednesday , August 5 2026
CISA

ALERT
CISA Warns of Active Attacks on Microsoft SharePoint and Zimbra

Cybersecurity and Infrastructure Security Agency (CISA) have added to its Known Exploited Vulnerabilities (KEV) Catalog. They included two serious flaws that cybercriminals are using. These flaws are a dangerous remote code execution (RCE) issue in Microsoft SharePoint and a stored cross-site scripting (XSS) problem in Zimbra Collaboration Suite. This shows the ongoing danger to both government and private businesses.

The worst of the two, CVE-2026-20963, is a serious security issue in Microsoft SharePoint. It has a CVSS score of 9.8. This problem comes from “deserialization of untrusted data,” a common weakness that lets an attacker run code over a network without any login details.

Thousands of data centers are at risk of compromise due to a 22-year-old flaw

Thousands of data centers are in danger because of a 22-year-old problem in Baseboard Management Controller (BMC) processors, says the...
Read More
Thousands of data centers are at risk of compromise due to a 22-year-old flaw

Bangladesh Launches (CIRS) and National ICT & Cyber Security Rating System (NRS)

In an important move to boost the country's cybersecurity, Bangladesh started the Cyber Incident Reporting System (CIRS) and the National...
Read More
Bangladesh Launches (CIRS) and National ICT & Cyber Security Rating System (NRS)

CVE-2026-18574
Check Point Authentication Bypass Hits Management Server

Check Point fixed a flaw that allowed bypassing authentication on its Security Management and Multi-Domain Security Management servers. This issue...
Read More
CVE-2026-18574  Check Point Authentication Bypass Hits Management Server

TP-Link RCE and SonicWall Zero-Click Flaws Enable Complete Device Compromise

TP-Link has shared a security warning about a serious problem with its TL-WR940N V6 wireless router. This problem, known as...
Read More
TP-Link RCE and SonicWall Zero-Click Flaws Enable Complete Device Compromise

ExfilSquad releases info of over 100,000 UK police officers, staff

A cyberattack on the U.K.'s Police National Legal Database (PNLD) has put the contact information of over 100,000 police officers...
Read More
ExfilSquad releases info of over 100,000 UK police officers, staff

CISA alerts to cyberattacks affecting U.S. water utilities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns of a big rise in attacks on internet-connected programmable logic controllers...
Read More
CISA alerts to cyberattacks affecting U.S. water utilities

“CyberStrike” AI-Driven Security Platform for Automated Testing

A new open-source project named CyberStrike aims to be the first AI tool made for offensive security. It can turn...
Read More
“CyberStrike” AI-Driven Security Platform for Automated Testing

AIDCQ Propose to invest $2 billion in AI data center in Bangladesh

Many countries are now showing interest to invest in the data center industry in Banglades especially in AI data centers....
Read More
AIDCQ Propose to invest $2 billion in AI data center in Bangladesh

NVIDIA BlueField Flaw Enables Code Execution Attacks

NVIDIA has revealed a big flaw with its BlueField DPUs and ConnectX networking systems. This issue could let attackers run...
Read More
NVIDIA BlueField Flaw Enables Code Execution Attacks

Massive customer data from India’s Bank of Baroda surfaced online

India's leading state-owned lender Bank of Baroda acknowledged Monday a security incident after reports that approximately 1 terabyte of customer...
Read More
Massive customer data from India’s Bank of Baroda surfaced online

In a typical network-based attack, a malicious actor could “write arbitrary code to inject and execute code remotely on the SharePoint Server”. Microsoft fixed this issue during its January Patch Tuesday. The bug moving to the KEV catalog means that hackers are still finding and attacking servers that have not been fixed.

The second addition, CVE-2025-66376, affects the Synacor Zimbra Collaboration Suite (ZCS). This weakness lets attackers perform “Classic UI stored XSS through CSS @import commands in an HTML email.”

An attacker can create a special email that has harmful styles. When the email is opened, these styles can make scripts run in the victim’s browser. This affects ZCS version 10 (before 10.0.18) and version 10.1 (before 10.1.13).

These vulnerabilities are common targets for hackers and can be very risky. The CISA rules mainly apply to federal agencies, but the KEV list is important for security teams all around. If CISA warns it’s being used in attacks, your organization is probably in danger if you haven’t made updates.

Check Also

5

TP-Link alerts users to patch router auth bypass vulnerability

TP-Link fixed some security flaws in its Archer NX routers. CVE-2025-15517 is a security flaw …