Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Organizations Warned of Exploited Cisco, Kentico, Zimbra Vulnerabilities
    Cybersecurity

    Organizations Warned of Exploited Cisco, Kentico, Zimbra Vulnerabilities

    adminBy adminApril 21, 2026No Comments2 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    CISA KEV
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The US cybersecurity agency CISA on Monday expanded its Known Exploited Vulnerabilities (KEV) catalog with eight more flaws, including three that have not previously been flagged as exploited.

    The most recent of these is CVE-2026-20133, a high-severity information disclosure bug in Cisco Catalyst SD-WAN Manager that was patched in February.

    Insufficient file system access restrictions could allow an attacker to access the API of an affected system and read information on the underlying operating system.

    The CVE was disclosed in February alongside CVE-2026-20122 and CVE-2026-20128, two SD-WAN flaws that Cisco flagged as exploited in March. Now, CISA has added all three to the KEV list.

    The agency also warned that two security defects disclosed last year in Kentico Xperience and Zimbra Collaboration Suite (ZCS), both leading to remote code execution (RCE), have been exploited in attacks.

    Tracked as CVE-2025-2749, the Kentico bug is described as a path traversal and arbitrary file upload issue that could allow attackers to execute content on the server remotely.

    Advertisement. Scroll to continue reading.

    The weakness exists because the Staging Sync Server of Kentico Xperience versions 13.0.178 and prior would upload arbitrary files to path-relative locations. Authentication is required for successful exploitation.

    In March last year, WatchTowr explained that hackers could chain three flaws in Kentico, including an authenticated RCE issue, to compromise deployments. Two of the weaknesses, tracked as CVE-2025-2746 and CVE-2025-2747, were added to CISA’s KEV catalog in October.

    The ZCS vulnerability that CISA added to KEV this week is CVE-2025-48700, an XSS bug in the Zimbra Classic UI that can be exploited to execute JavaScript code within the user’s session.

    Rooted in the insufficient sanitization of HTML content, the flaw can be triggered when the user opens a crafted message in the Classic UI.

    The other three flaws added to CISA’s KEV on Monday include CVE-2025-32975, a critical Quest KACE issue flagged as potentially exploited last month; CVE-2024-27199, a JetBrains TeamCity weakness exploited for over two years; and CVE-2023-27351, a PaperCut defect exploited since April 2023.

    CISA urges federal agencies to patch the Cisco and Zimbra vulnerabilities by April 23, and the other four issues by May 4.

    Related: Hackers Fail to Exploit Flaw in Discontinued TP-Link Routers

    Related: Recent Apache ActiveMQ Vulnerability Exploited in the Wild

    Related: Cursor AI Vulnerability Exposed Developer Devices

    Related: NIST Prioritizes NVD Enrichment for CVEs in CISA KEV, Critical Software

    Cisco Exploited Kentico organizations Vulnerabilities Warned Zimbra
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleYelp launches AI-powered Assistant to streamline local search and bookings
    Next Article Amazon’s $5B Anthropic bet is really about compute, not just cash
    admin
    • Website

    Related Posts

    CISA flags new SD-WAN flaw as actively exploited in attacks

    April 21, 2026

    CISA Adds 8 Exploited Flaws to KEV, Sets April-May 2026 Federal Deadlines

    April 21, 2026

    Researchers build an encrypted routing layer for private AI inference

    April 21, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    Explaining AMD gear modes and why they’re important for intensive workloads

    April 21, 2026

    CISA flags new SD-WAN flaw as actively exploited in attacks

    April 21, 2026

    Amazon’s $5B Anthropic bet is really about compute, not just cash

    April 21, 2026

    Organizations Warned of Exploited Cisco, Kentico, Zimbra Vulnerabilities

    April 21, 2026
    Categories
    • Blogging (66)
    • Cybersecurity (1,426)
    • Privacy & Online Earning (175)
    • SEO & Digital Marketing (865)
    • Tech Tools & Mobile / Apps (1,713)
    • WiFi / Internet & Networking (235)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    Explaining AMD gear modes and why they’re important for intensive workloads

    April 21, 2026

    CISA flags new SD-WAN flaw as actively exploited in attacks

    April 21, 2026

    Amazon’s $5B Anthropic bet is really about compute, not just cash

    April 21, 2026
    Most Popular
    • Explaining AMD gear modes and why they’re important for intensive workloads
    • CISA flags new SD-WAN flaw as actively exploited in attacks
    • Amazon’s $5B Anthropic bet is really about compute, not just cash
    • Organizations Warned of Exploited Cisco, Kentico, Zimbra Vulnerabilities
    • Yelp launches AI-powered Assistant to streamline local search and bookings
    • NotebookLM just launched a major update that is everything I wanted from the app
    • Why you should buy a 2025 Razr now
    • CISA Adds 8 Exploited Flaws to KEV, Sets April-May 2026 Federal Deadlines
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.