Find notable cyber news and cases, enriched with sources, timelines, and signals.

Synacor Zimbra CVE-2025-48700 security patch release

Security Patch Release
First reported
Last updated
Happening score
H score 76
1 unique sources, 1 articles

Summary

Hide ▲

Synacor released security patches for CVE-2025-48700, fixing an XSS flaw in Zimbra Classic UI that could be triggered by a malicious email and expose sensitive session data. The update covered ZCS 8.8.15, 9.0, 10.0, and 10.1, making the patch relevant to widely deployed email and collaboration servers. Because the bug required no user interaction beyond viewing the crafted message, unpatched systems remained exposed to low-friction exploitation.

Related Happenings

Zimbra Classic Web Client stored XSS security update

Security Patch Release
H score32 First: 10.07.2026 14:47 Last: 10.07.2026 14:47 Sources 1

About this happening: Zimbra released ZCS v10.1.19 to patch a stored XSS flaw in the Classic Web Client, narrowing exposure for users of that interface. The bug could be triggered through *...

Linux kernel Dirty Frag patch release (CVE-2026-43284, CVE-2026-43500)

Security Patch Release
H score32 First: 11.05.2026 17:30 Last: 11.05.2026 17:30 Sources 1

About this happening: Major Linux distributions are rolling out fixes for Dirty Frag, the Linux kernel patch release that covers CVE-2026-43284 and CVE-2026-43500. The update matter...

Linux kernel security update for Copy Fail (CVE-2026-31431)

Security Patch Release
H score39 First: 30.04.2026 16:54 Last: 30.04.2026 16:54 Sources 1

About this happening: Linux kernel maintainers have fixed CVE-2026-31431 and are rolling out updates to close a local privilege escalation flaw that lets an unprivileged attacker gain roo...

Microsoft April 2026 Patch Tuesday security update (165 CVEs)

Security Patch Release
H score62 First: 15.04.2026 00:22 Last: 15.04.2026 00:22 Sources 1

About this happening: Microsoft shipped April 2026 Patch Tuesday updates covering 165 CVEs, including an actively exploited zero-day and a publicly disclosed flaw, creating immediat...

Progress security patch release for CVE-2026-2699

Security Patch Release
H score68 First: 02.04.2026 16:33 Last: 02.04.2026 16:33 Sources 1

About this happening: Progress released ShareFile 5.12.4 on March 10 to fix CVE-2026-2699 and CVE-2026-2701 in the Storage Zones Controller (SZC) for branch 5.x. The update...

Timeline

  1. 24.04.2026 16:35 1 articles · 2mo ago

    Synacor Zimbra CVE-2025-48700 security patch release

    Initial Disclosure

    In June 2025, Synacor issued fixes for CVE-2025-48700 after warning that a crafted email viewed in Zimbra Classic UI could trigger the flaw without user interaction.

    Show sources