Find notable cyber news and cases, enriched with sources, timelines, and signals.

CISA KEV multi-product active exploitation wave (CVE-2020-7796)

Exploitation Wave
First reported
Last updated
Happening score
H score 53
1 unique sources, 1 articles

Summary

Hide ▲

CISA expanded its KEV catalog with four actively exploited flaws, signaling a live exploitation wave across Chrome, TeamT5 ThreatSonar, Zimbra, and Windows Video ActiveX Control. A GreyNoise-reported ~400-IP cluster was also tied to abuse of SSRF vulnerabilities, including CVE-2020-7796, against susceptible systems in multiple countries. FCEB agencies have a near-term remediation deadline of March 10, 2026.

Related Happenings

Joomla iCagenda and Balbooa Forms active RCE exploitation wave

Exploitation Wave
H score42 First: 13.07.2026 18:20 Last: 13.07.2026 18:20 Sources 1

About this happening: Joomla sites were hit by an active exploitation wave against iCagenda and Balbooa Forms upload flaws, enabling remote code execution and full website takeover....

Joomla extensions arbitrary file upload (multiple vulnerabilities, actively exploited)

Vulnerability
H score59 First: 13.07.2026 08:36 Last: 13.07.2026 08:36 Sources 1

About this happening: CISA added CVE-2026-48939 and CVE-2026-56291 to the KEV catalog, confirming zero-day exploitation of two Joomla extension flaws that allow arbitrary file u...

Zimbra Classic Web Client stored XSS security update

Security Patch Release
H score32 First: 10.07.2026 14:47 Last: 10.07.2026 14:47 Sources 1

About this happening: Zimbra released ZCS v10.1.19 to patch a stored XSS flaw in the Classic Web Client, narrowing exposure for users of that interface. The bug could be triggered through *...

Zimbra Classic Web Client stored XSS cross-site scripting flaw

Vulnerability
H score22 First: 10.07.2026 14:47 Last: 10.07.2026 14:47 Sources 1

About this happening: Zimbra's Classic Web Client stored cross-site scripting (XSS) flaw was patched in Zimbra 10.1.19, closing a path that could expose session data, account settings...

Microsoft 365 Copilot Enterprise SearchLeak remote code execution flaw (CVE-2026-42824)

Vulnerability
H score34 First: 15.06.2026 16:00 Last: 15.06.2026 16:00 Sources 1

About this happening: Microsoft 365 Copilot Enterprise Search has a critical vulnerability chain, SearchLeak, that could let a user leak emails, calendar details, MFA codes, and indexed f...

Timeline

  1. 18.02.2026 08:52 2 articles · 4mo ago

    CISA adds four actively exploited flaws to KEV catalog

    Legal Policy Action Update

    CISA added CVE-2026-2441 in Google Chrome, CVE-2024-7694 in TeamT5 ThreatSonar Anti-Ransomware versions 3.4.5 and earlier, CVE-2020-7796 in Synacor Zimbra Collaboration Suite (ZCS), and CVE-2008-0015 in Microsoft Windows Video ActiveX Control to the Known Exploited Vulnerabilities (KEV) catalog after evidence of active exploitation in the wild. CISA said Federal Civilian Executive Branch (FCEB) agencies should apply the necessary fixes by March 10, 2026, while Google said an exploit for CVE-2026-2441 exists in the wild and GreyNoise reported about 400 IP addresses abusing SSRF vulnerabilities, including CVE-2020-7796, against susceptible instances in multiple countries.

    Show sources