TL;DR
['CISA warns of actively exploited flaws in Zimbra and SharePoint that require urgent patching.', "CVE-2025-66376 is a stored XSS vulnerability affecting Synacor's ZCS.", 'Operators must act quickly to mitigate the risk of ransomware attacks.']
What happened
['CISA has issued an alert regarding two security flaws in Zimbra and SharePoint that have been exploited in recent attacks.', "CVE-2025-66376 is a stored cross-site scripting (XSS) vulnerability in Synacor's ZCS with a CVSS score of 7.2."]
Why it matters for ops
['The vulnerabilities allow attackers to inject malicious scripts into web pages, enabling them to steal session tokens or perform other actions on behalf of the user.', 'Failure to patch these flaws promptly can result in severe data breaches and ransomware attacks.']
Mitigation
- Apply available patches immediately.
- Disable untrusted user inputs and sanitize all data before rendering it as part of a webpage.
Action items
- Update software to the latest version.
- Review logs for any signs of exploitation.
- Inform security teams about this advisory.
Detection IOCs
- Unusual network traffic patterns
- Unexpected JavaScript execution in web applications
Source link
https://thehackernews.com/2026/03/cisa-warns-of-zimbra-sharepoint-flaw.html