CVE-2025-66376
Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
Yesterday's disclosures include two maximum-severity vulnerabilities in MLflow (CVE-2025-15379, CVSS 10.0) and Arch steam-trader (CVE-2026-5128, CVSS 10.0), alongside critical remote code execution flaws in WordPress, Nginx UI, and SciTokens. The disclosure volume includes 14 critical CVEsβdouble the prior day's count of 7βand 68 high-priority vulnerabilities, up 11% from 61. Actively exploited vulnerabilities affect Citrix NetScaler (CVE-2026-3055), Zimbra Collaboration Suite (CVE-2025-66376), Craft CMS (CVE-2025-32432), and three Apple product lines, with 9 KEV entries confirmed. Attack patterns center on remote code execution and authentication bypass across web frameworks, CMS platforms, and developer tooling. No patches are currently available for the disclosed vulnerabilities, making compensating controls and network-level mitigations essential in the interim.
Immediate action: Prioritize risk assessment for environments running MLflow, WordPress, Nginx UI, Citrix NetScaler, Zimbra, and Apple products, as these carry the highest severity scores and confirmed exploitation activity. With patch availability at 0%, implement compensating controls including network segmentation, WAF rules, and access restrictions for affected services until vendor fixes are released.
Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability - Active in CISA KEV catalog.
Citrix NetScaler Out-of-Bounds Read Vulnerability - Active in CISA KEV catalog.
Craft CMS Code Injection Vulnerability - Active in CISA KEV catalog.
Laravel Livewire Code Injection Vulnerability - Active in CISA KEV catalog.
Apple Multiple Products Improper Locking Vulnerability - Active in CISA KEV catalog.
Apple Multiple Products Classic Buffer Overflow Vulnerability - Active in CISA KEV catalog.
Apple Multiple Products Buffer Overflow Vulnerability - Active in CISA KEV catalog.
Langflow Code Injection Vulnerability - Active in CISA KEV catalog.
Aquasecurity Trivy Embedded Malicious Code Vulnerability - Active in CISA KEV catalog.
The Contact Form by Supsystic plugin for WordPress is vulnerable to unauthenticated Remote Code Execution via Server-Side Template Injection in the Twig template engine.
Everest Forms Pro is vulnerable to unauthenticated Remote Code Execution via PHP Code Injection in its Calculation Addon, allowing attackers to execute code through unsanitized form fields.
SciTokens is vulnerable to SQL Injection in its KeyCache class due to the unsafe use of Python's str.format() for query construction, allowing attackers to execute arbitrary SQL commands.
SourceCodester Sales and Inventory System 1.0 is vulnerable to Reflected Cross-Site Scripting (XSS) via the 'msg' parameter in add_stock.php due to insufficient input sanitization.
baserCMS contains an OS command injection vulnerability in its core update functionality, allowing authenticated administrators to execute arbitrary commands on the server.
Nginx UI versions 2.3.5 and prior are vulnerable to an authentication bypass on the /mcp_message endpoint, allowing unauthenticated attackers to take full control of the Nginx service.
CI4MS is vulnerable to stored Cross-Site Scripting (XSS) in its group and role management functionality, allowing attackers to execute malicious scripts in administrative views.
CI4MS is vulnerable to Stored DOM-Based Cross-Site Scripting in its Methods Management functionality, allowing for script execution in administrative and global navigation components.
A command injection vulnerability in MLflow's model serving container initialization allows attackers to execute arbitrary commands by supplying malicious model artifacts with unsanitized dependencies.
ArthurFiorette steam-trader 2.1.1 is vulnerable to unauthenticated sensitive information exposure, leaking Steam account credentials and 2FA secrets via API and logs.
OpenOlat fails to verify JWT signatures in its OpenID Connect implicit flow implementation, allowing attackers to bypass authentication by providing forged, unverified tokens.
A path traversal vulnerability in MLflow's archive extraction function allows attackers to overwrite arbitrary files and escape sandboxed directories via malicious tar archives.
Vim is vulnerable to arbitrary code execution when opening a crafted file due to a %{expr} injection flaw in the tabpanel component.
baserCMS contains an OS command injection vulnerability within its update functionality. Authenticated administrators can exploit this flaw to execute arbitrary commands with server-level privileges.
The Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2
Symantec Data Loss Prevention Windows Endpoint, prior to 25
Nginx UI is a web user interface for the Nginx web server
The Debugger & Troubleshooter plugin for WordPress was vulnerable to Unauthenticated Privilege Escalation in versions up to and including 1
The Download Monitor plugin for WordPress is vulnerable to an Insecure Direct Object Reference (IDOR) flaw. This allows unauthorized access to restricted files in versions up to 5.x.
Core FTP/SFTP Server 1
A security vulnerability has been detected in code-projects Accounting System 1
baserCMS is a website development framework
OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication
Invoice Ninja v5
A vulnerability was detected in SourceCodester Simple Doctors Appointment System 1
A flaw has been found in SourceCodester Simple Doctors Appointment System 1
The Performance Library component of Gigabyte Control Center has an Insecure Deserialization vulnerability
A vulnerability was detected in Tenda FH1201 1
A flaw has been found in Tenda FH1201 1
A vulnerability was detected in Tenda CH22 1
A vulnerability has been found in Tenda CH22 1
A vulnerability was found in Tenda CH22 1
A vulnerability was determined in Tenda CH22 1
A cross-session information disclosure vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80a9877fab52acacf7ab8251 (2026-01-19)
act is a project which allows for local running of github actions
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14
Gigabyte Control Center developed by GIGABYTE has an Arbitrary File Write vulnerability
OpenClaw before 2026
Unauthenticated credential disclosure in the wizard interface in ZTE ZXHN H188A V6
An unauthenticated remote attacker can exploit insufficient input validation to access backend components beyond their intended scope via path traversal, resulting in exposure of sensitive information
An integer overflow vulnerability in the HTTP chunked transfer encoding parser in tinyproxy up to and including version 1
FreeRDP, an open-source Remote Desktop Protocol implementation, contains a security vulnerability. This flaw could potentially allow remote attackers to compromise RDP sessions or execute unauthorized actions.
FreeRDP is affected by a security vulnerability that could lead to unauthorized access or data compromise. This issue resides within the protocol implementation and affects various versions of the software.
FreeRDP is a free implementation of the Remote Desktop Protocol
FreeRDP is a free implementation of the Remote Desktop Protocol
SQL Injection vulnerability in SchemaHero 0
SQL Injection vulnerability in SchemaHero 0
A security flaw has been discovered in the Belkin F9K1122 router, potentially allowing for unauthorized access or system interference.
A security weakness has been identified in the Belkin F9K1122 router that could be exploited to compromise the device's security posture.
OpenClaw before 2026
OpenClaw before 2026
OpenClaw before 2026
A security vulnerability has been detected in the Belkin F9K1122 router, potentially enabling attackers to gain unauthorized access or disrupt services.
A critical vulnerability exists in the Sofia component of Xiongmai DVR/NVR devices. This flaw allows attackers to potentially compromise the surveillance system's integrity and availability.
Ghidra versions prior to 12
Moby is an open source container framework
baserCMS is a website development framework
OpenClaw before 2026
OpenClaw before 2026
OpenClaw before 2026
A critical security vulnerability in parisneo/lollms versions up to 2
Botan is a C++ cryptography library
SciTokens is a reference library for generating and using SciTokens
SciTokens is a reference library for generating and using SciTokens
OpenClaw before 2026
TrueConf Client downloads application update code and applies it without performing verification
vcpkg is a free and open-source C/C++ package manager
In KubePlus 4
Grav CMS v1
OpenClaw before 2026
A vulnerability in parisneo/lollms, up to and including version 2
A Server-Side Request Forgery (SSRF) vulnerability exists in parisneo/lollms versions prior to 2
OpenAirInterface V2
A vulnerability exists in the iconv() function of the GNU C Library (glibc) version 2. This flaw can lead to unexpected behavior or potential security bypasses during character set conversion.
A flaw in Node
LangChain is a framework for building agents and LLM-powered applications
OpenClaw before 2026
A security flaw has been discovered in YunaiV yudao-cloud up to 2026
A security flaw has been discovered in Totolink A3300R 17
A vulnerability was found in SourceCodester Teacher Record System 1
OpenClaw before 2026
baserCMS is a website development framework