Sploitus Critical Vulnerabilities in Piwigo and Zimbra Expose Users to Remote Attacks
Article Content
- •CVE-2026-62262 allows SQL injection in Piwigo, exposing sensitive data.
- •CVE-2026-93643 enables remote command execution in Zimbra via path traversal.
- •Both vulnerabilities are critical with CVSS scores above 9.0; patches are available.
Two critical vulnerabilities, CVE-2026-62262 and CVE-2026-93643, have been disclosed affecting Piwigo and Zimbra software. CVE-2026-62262 allows unauthenticated SQL injection attacks on Piwigo versions 17.0.0beta1 and earlier, enabling attackers to extract sensitive database information. CVE-2026-93643 exposes Zimbra's OnlyOffice integration to unauthenticated remote command execution through path traversal, affecting users with access to public Briefcase documents. Both vulnerabilities have a CVSS score above 9.0, indicating their critical nature. No public proof-of-concept exploits are available yet, but organizations are urged to apply patches as soon as possible. The vulnerabilities were published on September 25, 2026, and are currently not listed in CISA's Known Exploited Vulnerabilities catalog. Security teams should monitor logs for anomalous activities related to these vulnerabilities.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track CVE-2026-62262 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed