The U.S. Cybersecurity and Infrastructure Security Agency ( CISA ) has issued an urgent warning about two critical security vulnerabilities affecting Zimbra Collaboration Suite and Microsoft SharePoint , as active attacks have been identified. Meanwhile, Amazon revealed that hackers linked to the Interlock ransomware are exploiting a zero-day vulnerability in Cisco 's firewall management software .

The first vulnerability, CVE-2025-66376 with a CVSS score of 7.2, concerns a stored cross-site scripting (XSS) vulnerability in the Classic UI of Synacor Zimbra Collaboration Suite. Attackers can exploit Cascading Style Sheets (CSS) @import directives in HTML email messages to inject malicious code. The vulnerability was fixed in versions 10.0.18 and 10.1.13 in November 2025.
See also: Microsoft SharePoint Server zero-day attack affects African Ministry of Finance
The second vulnerability, CVE-2026-20963 with a higher CVSS score of 8.8 , is an untrusted data deserialization vulnerability in Microsoft Office SharePoint . This vulnerability allows unauthorized attackers to execute code over a network, and was patched in January 2026 .
Abuse of vulnerabilities
The addition of CVE-2025-66376 to the Known Exploited Vulnerabilities (KEV) list marks a particularly worrying development in the cybersecurity field, as it is linked to a targeted espionage campaign allegedly supported by Russian state agencies. The campaign, dubbed Operation GhostMail, was uncovered following research by Seqrite Labs and primarily targeted the State Hydrographic Service of Ukraine.

Unlike traditional phishing attacks, this particular campaign relied on a highly sophisticated social engineering technique. The attackers sent emails that did not contain malicious attachments, suspicious links, or macros, elements that typically trigger detection mechanisms.
Instead, the entire attack payload was embedded in the HTML body of the email itself. Through carefully crafted and obfuscated JavaScript code, the attackers exploited an XSS vulnerability in Zimbra webmail, allowing malicious code to be executed directly from within the user's session.
The attack is triggered the moment the victim opens the email in a vulnerable webmail environment. Without any further action being required, the embedded JavaScript begins collecting critical data from the user's system and browser.
See also: ToolShell Zero-Day Attacks on SharePoint-Linked to China?
Specifically, the malicious script is able to extract login credentials, session tokens, backup codes for two-factor authentication (2FA), saved passwords, and the full content of the Inbox for up to 90 days. This data is sent to the attackers via DNS and HTTPS channels, making detection even more difficult.
Connection to previous Russian cyber operations
Operation GhostMail is not an isolated incident, but is part of a broader pattern of attacks attributed to Russian state actors. Similar techniques were also observed in Operation RoundPress, which exploited XSS vulnerabilities in webmail platforms to compromise Ukrainian organizations.
The repeated use of these techniques shows a strategic focus on webmail as a primary entry point, given that it is a critical communication tool for government and military organizations.

SharePoint vulnerability CVE-2026-20963 allows remote code execution by exploiting deserialization issues. This type of vulnerability is particularly dangerous as it can lead to a complete system compromise, allowing attackers to execute arbitrary code with the privileges of the application. There are currently no public reports of exploitation of this vulnerability.
CISA urges federal FCEB agencies to implement patches for CVE-2025-66376 by April 1, 2026, and for CVE-2026-20963 by March 23, 2026.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Additionally, organizations should educate users about the risks of opening emails from untrusted sources, particularly those containing HTML content. Security teams should review email security controls and consider implementing additional filtering for emails with CSS directives or references to external resources.
See also: Microsoft: Emergency updates for SharePoint zero-day vulnerabilities
Cisco zero-day and Interlock ransomware attacks
Alongside CISA ’s warnings , Amazon revealed that threat groups linked to the Interlock ransomware are exploiting a critical security vulnerability in Cisco ’s firewall management software . The vulnerability, CVE-2026-20131, has a maximum CVSS score of 10.0 and has been used in attacks since January 26, 2026 .
Interlock ransomware has historically targeted specific sectors where operational disruption creates maximum pressure for payment. These sectors include education, engineering, architecture, construction, manufacturing, industrial, healthcare, and government organizations.
