U.S. CISA adds Microsoft SharePoint and Zimbra  flaws to its Known Exploited Vulnerabilities catalog
嗯,用户让我帮忙总结一篇文章,控制在100字以内,而且不需要用“文章内容总结”之类的开头。我先看看这篇文章讲的是什么。 文章主要讲的是美国网络安全和基础设施安全局(CISA)将微软SharePoint和Zimbra的漏洞加入到已知被利用的漏洞目录中。具体来说,有两个漏洞:CVE-2026-20963和CVE-2025-66376。前者是SharePoint的反序列化漏洞,CVSS评分8.8;后者是Zimbra的跨站脚本漏洞,评分7.2。 CISA要求联邦机构在特定日期前修复这些漏洞,分别是2026年3月21日和4月1日。同时建议私营组织也检查并修复这些漏洞。 好的,现在我需要把这些信息浓缩到100字以内。要包括CISA、漏洞名称、CVE编号、评分、影响以及修复期限。 可能的结构:CISA将SharePoint和Zimbra的两个高危漏洞加入目录,要求机构在指定日期前修复。 再检查一下字数,确保不超过限制。这样应该可以满足用户的需求了。 </think> 美国网络安全机构CISA将微软SharePoint反序列化漏洞(CVE-2026-20963,CVSS 8.8)和Zimbra跨站脚本漏洞(CVE-2025-66376,CVSS 7.2)加入已知被利用漏洞目录,并要求联邦机构分别于2026年3月21日和4月1日前修复。 2026-3-18 21:11:38 Author: securityaffairs.com(查看原文) 阅读量:11 收藏

U.S. CISA adds Microsoft SharePoint and Zimbra  flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds SharePoint and Zimbra flaws to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added ([1, 2]) SharePoint and Zimbra flaws to its Known Exploited Vulnerabilities (KEV) catalog.

Below are the flaws added to the catalog:

  • CVE-2026-20963 (CVSS score of 8.8) – Microsoft SharePoint Deserialization of Untrusted Data Vulnerability;
  • CVE-2025-66376 (CVSS score of 7.2) –  Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability;

The first vulnerability added to the catalog, tracked as CVE-2026-20963, is a deserialization of untrusted data in Microsoft Office SharePoint that allows an authorized attacker to execute code over a network.

“In a network-based attack, an unauthenticated attacker could write arbitrary code to inject and execute code remotely on the SharePoint Server.” reads the advisory.

The second flaw added to the KeV catalog, tracked as CVE-2025-66376, is a stored XSS vulnerability in the Classic UI where attackers could abuse CSS @import directives in email HTML.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the vulnerability CVE-2026-20963 by March 21, 2026 and the flaw CVE-2025-66376 by April 1st, 2026.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)




文章来源: https://securityaffairs.com/189628/security/u-s-cisa-adds-microsoft-sharepoint-and-zimbra-flaws-to-its-known-exploited-vulnerabilities-catalog.html
如有侵权请联系:admin#unsafe.sh