CyberConfirmedMediumDeveloping
9.5
Critical command injection vulnerability identified in Zimbra Collaboration Suite
Zimbra has released patches for a critical command injection vulnerability affecting servers with SNMP notifications enabled, alongside fixes for four XSS flaws and a mail-forwarding bypass. The extent of active exploitation remains unconfirmed, but the severity of the injection flaw poses a significant risk to enterprise email infrastructure.
Score Breakdown
Mosaic Score9.5
Confidence0.9
Significance0.5
Source credibility0.5
Intelligence Tags
Part of a situation
Related signals
8 foundCyberNotableConfirmedDeveloping
10.0
SecurityWeek·about 13 hours ago
CyberNotableConfirmedDeveloping
10.0
Unofficial patches released for Windows LegacyHive privilege escalation zero-day
BleepingComputer·US·about 13 hours ago
CyberHighConfirmedAccelerating
10.0
Qilin ransomware group exploiting critical Palo Alto Networks PAN-OS authentication bypass
BleepingComputer·US·about 11 hours ago
CyberHighConfirmedAccelerating
10.0
Google develops autonomous vulnerability discovery and exploitation AI
The Hacker News·US·about 6 hours ago
CyberHighConfirmedAccelerating
10.0
Critical pre-authentication sandbox escape vulnerability identified in ServiceNow AI platform
The Hacker News·about 14 hours ago
CyberHighConfirmedAccelerating
10.0
Active exploitation of critical WordPress wp2shell vulnerabilities detected
BleepingComputer·about 4 hours ago
CyberHighConfirmedAccelerating
7.7
Active exploitation of SharePoint RCE vulnerability CVE-2026-50522 enables persistent access
The Hacker News·US·about 6 hours ago
TechSingle-source
2.2
Cisco releases open-weight Antares AI models for automated code vulnerability detection
SecurityWeek·US·about 3 hours ago