CISA KEV multi-product active exploitation wave (CVE-2020-7796)
Exploitation Wave
Summary
Hide ▲
Show ▼
CISA expanded its KEV catalog with four actively exploited flaws, signaling a live exploitation wave across Chrome, TeamT5 ThreatSonar, Zimbra, and Windows Video ActiveX Control. A GreyNoise-reported ~400-IP cluster was also tied to abuse of SSRF vulnerabilities, including CVE-2020-7796, against susceptible systems in multiple countries. FCEB agencies have a near-term remediation deadline of March 10, 2026.
Related Happenings
Joomla iCagenda and Balbooa Forms active RCE exploitation wave
Exploitation Wave
H score42
First: 13.07.2026 18:20
Last: 13.07.2026 18:20
Sources 1
About this happening:
Joomla sites were hit by an active exploitation wave against iCagenda and Balbooa Forms upload flaws, enabling remote code execution and full website takeover....
Joomla iCagenda and Balbooa Forms active RCE exploitation wave
Exploitation WaveAbout this happening: Joomla sites were hit by an active exploitation wave against iCagenda and Balbooa Forms upload flaws, enabling remote code execution and full website takeover....
Joomla extensions arbitrary file upload (multiple vulnerabilities, actively exploited)
Vulnerability
H score59
First: 13.07.2026 08:36
Last: 13.07.2026 08:36
Sources 1
About this happening:
CISA added CVE-2026-48939 and CVE-2026-56291 to the KEV catalog, confirming zero-day exploitation of two Joomla extension flaws that allow arbitrary file u...
Joomla extensions arbitrary file upload (multiple vulnerabilities, actively exploited)
VulnerabilityAbout this happening: CISA added CVE-2026-48939 and CVE-2026-56291 to the KEV catalog, confirming zero-day exploitation of two Joomla extension flaws that allow arbitrary file u...
Zimbra Classic Web Client stored XSS security update
Security Patch Release
H score32
First: 10.07.2026 14:47
Last: 10.07.2026 14:47
Sources 1
About this happening:
Zimbra released ZCS v10.1.19 to patch a stored XSS flaw in the Classic Web Client, narrowing exposure for users of that interface. The bug could be triggered through *...
Zimbra Classic Web Client stored XSS security update
Security Patch ReleaseAbout this happening: Zimbra released ZCS v10.1.19 to patch a stored XSS flaw in the Classic Web Client, narrowing exposure for users of that interface. The bug could be triggered through *...
Zimbra Classic Web Client stored XSS cross-site scripting flaw
Vulnerability
H score22
First: 10.07.2026 14:47
Last: 10.07.2026 14:47
Sources 1
About this happening:
Zimbra's Classic Web Client stored cross-site scripting (XSS) flaw was patched in Zimbra 10.1.19, closing a path that could expose session data, account settings...
Zimbra Classic Web Client stored XSS cross-site scripting flaw
VulnerabilityAbout this happening: Zimbra's Classic Web Client stored cross-site scripting (XSS) flaw was patched in Zimbra 10.1.19, closing a path that could expose session data, account settings...
Microsoft 365 Copilot Enterprise SearchLeak remote code execution flaw (CVE-2026-42824)
Vulnerability
H score34
First: 15.06.2026 16:00
Last: 15.06.2026 16:00
Sources 1
About this happening:
Microsoft 365 Copilot Enterprise Search has a critical vulnerability chain, SearchLeak, that could let a user leak emails, calendar details, MFA codes, and indexed f...
Microsoft 365 Copilot Enterprise SearchLeak remote code execution flaw (CVE-2026-42824)
VulnerabilityAbout this happening: Microsoft 365 Copilot Enterprise Search has a critical vulnerability chain, SearchLeak, that could let a user leak emails, calendar details, MFA codes, and indexed f...
Timeline
-
18.02.2026 08:52 2 articles · 4mo ago
CISA adds four actively exploited flaws to KEV catalog
Legal Policy Action UpdateCISA added CVE-2026-2441 in Google Chrome, CVE-2024-7694 in TeamT5 ThreatSonar Anti-Ransomware versions 3.4.5 and earlier, CVE-2020-7796 in Synacor Zimbra Collaboration Suite (ZCS), and CVE-2008-0015 in Microsoft Windows Video ActiveX Control to the Known Exploited Vulnerabilities (KEV) catalog after evidence of active exploitation in the wild. CISA said Federal Civilian Executive Branch (FCEB) agencies should apply the necessary fixes by March 10, 2026, while Google said an exploit for CVE-2026-2441 exists in the wild and GreyNoise reported about 400 IP addresses abusing SSRF vulnerabilities, including CVE-2020-7796, against susceptible instances in multiple countries.
Show sources
- CISA Flags Four Security Flaws Under Active Exploitation in Latest KEV Update — thehackernews.com — 18.02.2026 08:52
- CISA Flags Four Security Flaws Under Active Exploitation in Latest KEV Update — thehackernews.com — 18.02.2026 08:52