SharePoint and Zimbra Under Siege

Article by Nacata Security, 30/07/2026

Does your company use SharePoint or Zimbra for daily teamwork?

Two critical vulnerabilities are being actively exploited right now.

We are not talking about theoretical or lab-based flaws: Check Point issued specific protections this week because exploitation attempts are already real and ongoing.

When a cybersecurity firm publishes active protections for a specific CVE, it means someone, somewhere, is already trying to walk through that door.

Illustration of remote code execution exploitation on a corporate server of the SharePoint type
Server Under Siege

The first is a remote code execution flaw.

CVE-2026-50522 affects Microsoft SharePoint and allows arbitrary code execution on the server without requiring valid credentials. Any attacker from anywhere on the planet can take control of your corporate collaboration environment, read internal documents, move laterally across the network, or deploy an additional payload. SharePoint is not optional for many organizations — it is the document backbone of their daily operations.

The second flaw turns your browser into the weapon.

CVE-2025-66376 strikes Zimbra Collaboration Suite through a cross-site scripting attack. Here the vector shifts: the server is not attacked directly, but rather the user who opens their email in the browser. A carefully crafted malicious email can inject code into the active session, steal credentials, hijack the session, or redirect the user to phishing pages without them noticing anything unusual.

Two different products, two different vectors, one shared urgency to patch.

Visualization of the cross-site scripting attack on Zimbra that compromises the user session from the browser
Session Silently Hijacked

The risk does not wait for you to react.

What makes this week especially dangerous is the combination: a flaw at the server layer and another at the user layer, covering nearly every angle of entry. If your organization runs either of these platforms unpatched, it is exposed right now.

Zimbra and SharePoint are not niche tools.

SharePoint handles internal documentation for organizations of all sizes, from small businesses to large enterprises. Zimbra is a widely deployed email and collaboration alternative used in public administrations, universities, and companies that prefer self-hosted solutions. Targeting these platforms is a deliberate strategy to maximize impact, because a single breach can open access to the entire corporate network.

Representation of the lateral reach of an attack originating from a single breach in large-scale collaboration platforms
One Breach, Everything

An unpatched server is an open invitation to an attacker.

The active exploitation detected this week indicates that attackers already have a functional exploit for both CVEs. Every hour without patching is an hour in which your infrastructure could be the next target of a mass scan.

Response speed makes all the difference.

Historically, attackers scale their campaigns within days once an exploit is confirmed functional in real-world environments. The pattern is well known: first targeted attacks, then automated waves sweeping the internet in search of vulnerable versions. If your IT team has not yet received the alert, now is the time to pass it along.

Patch today, not next week.

The question is not whether these flaws affect you, but whether you have already taken action before someone decides to find out for you.

What to do now

  • Apply the SharePoint patch for CVE-2026-50522 immediately.
  • Update Zimbra Collaboration Suite to remediate the cross-site scripting flaw.
  • Review access logs for anomalous activity.

Do you know exactly which version of SharePoint or Zimbra is running in your organization right now?

Security is not improvised, it is audited. At Nacata Security we detect vulnerabilities and protect your company, because a single flaw can cost you everything you have built.

Related articles

Nacata Security, reach out to us anytime

How would you rate this news?

We are Nacata Security, get to know us

web: nacata.io

email: info@nacata.io

Phone: 919930793

LinkedIn: Nacata Security

Threats

Risks and attacks happening right now: vulnerabilities being actively exploited, official alerts from cybersecurity agencies, ongoing phishing or malware campaigns.

Information meant to help you act and protect yourself before the problem reaches you.



RATING


8.8



Who are we?


At Nacata Security we are an offensive cybersecurity company specialized in audits and penetration testing.


We detect, assess and help mitigate the vulnerabilities of your systems, networks and applications before a real attacker exploits them, offering 360º defense tailored to each client.


We’d be glad to get in touch with you for whatever you need.