The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has urged government agencies to apply patches for two security flaws impacting Synacor Zimbra Collaboration Suite (ZCS) and Microsoft Office SharePoint, stating they have been actively exploited in the wild. The vulnerabilities in question are as follows -
CVE-2025-66376 (CVSS score: 7.2) - A stored cross-site scripting
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
