Skip to content
Critical Vulnerabilities in Piwigo and Zimbra Expose Users to Remote Attacks

Critical Vulnerabilities in Piwigo and Zimbra Expose Users to Remote Attacks

First seen 27 Sep 2026, 03:54 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 27, 2026 at 18:20 UTC
  • •CVE-2026-62262 allows SQL injection in Piwigo, exposing sensitive data.
  • •CVE-2026-93643 enables remote command execution in Zimbra via path traversal.
  • •Both vulnerabilities are critical with CVSS scores above 9.0; patches are available.

Two critical vulnerabilities, CVE-2026-62262 and CVE-2026-93643, have been disclosed affecting Piwigo and Zimbra software. CVE-2026-62262 allows unauthenticated SQL injection attacks on Piwigo versions 17.0.0beta1 and earlier, enabling attackers to extract sensitive database information. CVE-2026-93643 exposes Zimbra's OnlyOffice integration to unauthenticated remote command execution through path traversal, affecting users with access to public Briefcase documents. Both vulnerabilities have a CVSS score above 9.0, indicating their critical nature. No public proof-of-concept exploits are available yet, but organizations are urged to apply patches as soon as possible. The vulnerabilities were published on September 25, 2026, and are currently not listed in CISA's Known Exploited Vulnerabilities catalog. Security teams should monitor logs for anomalous activities related to these vulnerabilities.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-25
CVE-2026-93643 published
Critical vulnerability in Zimbra's OnlyOffice integration disclosed, allowing RCE.
Sploitus
2026-09-25
CVE-2026-62262 published
Piwigo vulnerability disclosed, allowing SQL injection attacks on database information.
TheHackerWire
2026-09-27
Critical vulnerabilities reported
Two critical vulnerabilities affecting Piwigo and Zimbra reported, urging immediate patching.
TheHackerWire

More articles in this cluster (5)

Following this threat?

Track CVE-2026-62262 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed