< ciso
brief />
Tag Banner

All news with #cross site scripting tag

42 articles

New CSS attack chains break webmail boundaries

🔒 New research shows HTML and CSS can escape email message boundaries to interfere with webmail UIs across major providers. PortSwigger researcher Gareth Heyes presented proof-of-concept chains at Black Hat USA 2026 targeting Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail. The techniques can capture passwords, leak tokens, hijack UI actions, and manipulate AI-connected tools; some PoCs remained public as of August 8.
read more →

WordPress pre-auth XSS patched in 7.0.3 release

🔒 WordPress patched a pre-auth reflected XSS in the login screen (CVE-2026-64638) that requires no attacker privileges and can execute JavaScript when a crafted username reaches the failed-login page. Researchers at pwn.ai demonstrated chaining the XSS to PHP code execution if an Administrator interacts with an attacker-controlled page, and WordPress issued fixes on August 6 across supported branches.
read more →

Russian hackers exploit Exchange OWA to hijack mailboxes

📧 A Russia-aligned group, tracked as TA488 (Void Blizzard/Laundry Bear), began a campaign on July 22 using a “half-click” exploit in Microsoft Exchange Outlook Web Access to install a browser-based backdoor when recipients viewed specially crafted emails. The attackers abused CVE-2026-42897, a cross-site scripting flaw allowing JavaScript to run inside OWA without clicking links or opening attachments. The implant, named OWAReaper, removes evidence from stored messages, harvests account data, and can leverage Outlook add-ins to obtain OAuth tokens and owner-level mailbox access, creating server-side persistence that typical endpoint-focused defenses may miss.
read more →

Zimbra update fixes nine critical vulnerabilities

🔒 Zimbra Collaboration Suite 10.1.20 addresses nine vulnerabilities across commercial and open-source editions, including a permanent fix for an SNMP command injection flaw and four XSS issues in the Classic Web Client. The update also patches mailbox delegation and EWS access control problems, an SSRF in Nextcloud integration, and a bypass for email forwarding restrictions. Synacor urges administrators to upgrade promptly to prevent exploitation by threat actors.
read more →

Adobe Acrobat Chrome Extension UXSS Flaw Exposes Data

🛡️ Researchers disclosed a now-patched vulnerability chain in the Adobe Acrobat Chrome extension (ID: efaidnbmnnnibpcajpcglclefindmkaj) affecting versions up to 26.5.2.2. Tracked as CVE-2026-48294 and dubbed HermeticReader by Guardio Labs, the UXSS-class issue (CVSS 7.4) allowed cross-origin read access to session-bound data after simple user interaction. Exploitation required visiting a crafted page that triggers the extension's vulnerable code path, enabling attackers to extract WhatsApp Web content without credentials or malware.
read more →

Adobe Chrome extension flaw exposed WhatsApp data

🔒 The Adobe Acrobat extension for Chrome contained a chain of vulnerabilities (CVE-2026-48294, dubbed HermeticReader) that let attacker-controlled websites access conversations and other data rendered in WhatsApp Web without authentication. Guardio researchers showed the flaw allowed web pages to write into the extension's storage, activate its WhatsApp integration (Hermes), and issue DOM-manipulating commands to a WhatsApp tab. Adobe patched the issue in version 26.5.2.3; users should ensure they have the update.
read more →

Zimbra issues patch for critical SNMP command flaw

🔧 Zimbra released version 10.1.20 to address nine vulnerabilities, led by a command injection flaw in the SNMP monitoring component when SNMP notifications are enabled. The update also fixes four cross-site scripting (XSS) issues in the Classic Web Client and a mail forwarding restriction bypass (CVE-2026-50055) reported by Jonah Burgess. The vendor limited details per industry best practices and urged customers to apply the fixes promptly.
read more →

Critical Opera GX mod flaw allowed cross‑site data theft

🔒 An independent researcher discovered a critical vulnerability in Opera GX where GX Mods auto-install on download with no permission prompt, allowing an attacker to inject CSS across all pages. This behavior enabled a zero-click XS-Leak to recover a victim's Gmail address and facilitated a DoS crash when mods were forced into private mode. The issue was reported in February, patched on May 8, and the PoC was published on July 3.
read more →

Microsoft patches Exchange Server XSS zero-day exploit

🛡️ Microsoft released updates to fix an actively exploited Exchange Server XSS vulnerability (CVE-2026-42897) that allows remote attackers to execute arbitrary JavaScript in Outlook Web Access without privileges. The flaw affects Exchange Server 2016, 2019, and Subscription Edition; Microsoft initially deployed a temporary mitigation via the Exchange Emergency Mitigation Service and now urges admins to install the June 2026 security updates and retain mitigations for added protection.
read more →

ABB EIBPORT XSS Vulnerability and Firmware Patch

🔒 ABB disclosed a cross-site scripting vulnerability in affected ABB EIBPORT firmware versions that can expose session identifiers and allow unauthorized access. A firmware update is available that modifies session and credential handling and hardens product configuration. ABB recommends applying the update promptly and following network segmentation and firewall best practices to reduce exposure.
read more →

Kieback & Peter DDC Controllers Vulnerable to XSS Alert

⚠️ A cross-site scripting vulnerability (CWE-79, CVSS v3 5.3) affects multiple Kieback & Peter DDC Building Controllers and can enable execution of arbitrary JavaScript in a victim's browser, potentially allowing attacker control of web sessions. Affected models include end-of-maintenance units (DDC4002, DDC4100, DDC4200, DDC4200-L, DDC4400) and e-series controllers (DDC520, DDC4002e, DDC4200e, DDC4400e, DDC4020e, DDC4040e). The vendor advises isolating legacy devices, restricting and disabling web access where possible, and updating e-series firmware to the specified versions (e.g., DDC520 -> 1.24.2; DDC4002e/DDC4200e/DDC4400e/DDC4020e/DDC4040e -> 1.23.5) while implementing defense-in-depth controls.
read more →

Emergency Zero-Day in Exchange Server Forces Mitigations

⚠️Microsoft has warned of a zero-day cross-site scripting vulnerability in Exchange Outlook Web Access (OWA) that can be triggered by a specially crafted email. The flaw (CVE-2026-42897) is being actively exploited and affects Exchange Server 2016, 2019, and Server Subscription Edition, while Exchange Online is unaffected. Microsoft has published an automatic mitigation via the Exchange EM Service; administrators should enable EM Service or run the Exchange on-premises Mitigation Tool (EOMT) if servers are air-gapped. The interim mitigations can disrupt OWA features such as calendar printing and inline image display, and a formal security update will be released later.
read more →

Microsoft warns of Exchange Server zero-day XSS flaw

⚠️ Microsoft has disclosed a high-severity zero-day, CVE-2026-42897, in on-premises Exchange Server that could allow an attacker to execute arbitrary code by sending a specially crafted email to an Outlook user. The flaw is an XSS vulnerability affecting all supported versions of Exchange 2016, 2019 and Subscription Edition, but not Exchange Online. Microsoft recommends enabling the Exchange Emergency Mitigation (EM) Service, which is applied by default, and provides an alternative manual mitigation via the Exchange On-premises Mitigation Tool for air-gapped environments while patches are developed.
read more →

Microsoft: Exchange Server XSS flaw actively exploited

⚠️ Microsoft disclosed a new actively exploited vulnerability, CVE-2026-42897 (CVSS 8.1), a spoofing bug caused by cross-site scripting in on-premises Exchange Server. An attacker can execute arbitrary JavaScript by sending a crafted email that is opened in Outlook Web Access. Microsoft offers a temporary mitigation via the Exchange Emergency Mitigation Service (enabled by default) and provides an EOMT PowerShell script for environments that cannot use the service; Exchange Online is not affected.
read more →

Siemens SIMATIC S7 Web Server Cross-Site Scripting Risks

⚠ Siemens SIMATIC S7 PLC web servers contain multiple cross-site scripting (XSS) vulnerabilities in their web interfaces that could allow an authenticated user with rights to download TIA projects to inject malicious scripts. Affected pages include the Communication parameters, Motion Control Diagnostics, and Firmware Update pages, where names or filenames are not properly sanitized. Siemens has published updates for several affected firmware lines—update to V2.9.9 or V3.1.6 or later where available—and is preparing further fixes. CISA republished the advisory and recommends restricting project downloads and firmware update rights, isolating devices, and applying vendor updates or compensating controls.
read more →

Siemens Teamcenter vulnerabilities: patches and guidance

🔔 Siemens disclosed multiple vulnerabilities in Teamcenter that could affect availability, integrity, and confidentiality of affected installations. The vendor published patches across several builds and recommends administrators update to the indicated fixed versions (examples include V2312.0009, V2406.0006, V2412.0009, V2506.0005 and later). Identified issues include improper error checking (CWE-754), cross-site scripting (CWE-79), and hard‑coded credentials (CWE-798). CISA and Siemens advise minimizing network exposure, isolating control systems, applying vendor updates promptly, and following Siemens' industrial security guidance.
read more →

Instructure Reaches Agreement with ShinyHunters, Data Returned

🛡️ Instructure says it reached an agreement with ShinyHunters after a breach of its Canvas LMS that exposed usernames, emails, course names, enrollments, and messages. The actor returned the stolen data and supplied shred logs confirming destruction. Instructure attributes the intrusion to XSS flaws in the Free-for-Teacher environment, has restored Canvas, and temporarily disabled that free tier while investigating and monitoring activity.
read more →

CISA: Over 10,000 Zimbra Servers Vulnerable to XSS

⚠️ Shadowserver and CISA warn that more than 10,500 internet-exposed Zimbra Collaboration Suite instances remain vulnerable to an actively exploited cross-site scripting bug tracked as CVE-2025-48700. Synacor issued patches in June 2025, but the flaw can be triggered without user interaction when a maliciously crafted email is viewed in the Classic UI. CISA added the issue to its Known Exploited Vulnerabilities catalog and ordered federal agencies to secure affected servers by April 23.
read more →

Tip-line Breach and Rockstar Leak Highlight Security Risks

🔐 A tip‑line operator that handled anonymous reports for 35,000 U.S. schools suffered a major breach after an attacker exploited an XSS flaw in a LeverTip chat box and stole a staff session cookie via social engineering. The intruder exfiltrated 91 GB (≈8.3M tip records), some dating back decades, and offered the dataset for sale. Separately, Rockstar Games experienced a third‑party compromise that exposed partial data, including internal financial figures. Both incidents underscore failures in basic web hygiene, third‑party controls, and incident transparency.
read more →

Schneider Electric Modicon Controllers XSS Advisory

🔒 CISA warns of a cross-site scripting and open redirect vulnerability (CVE-2025-13902) affecting Schneider Electric Modicon controllers M241, M251, M258, and LMC058. Successful exploitation may enable account takeover or arbitrary JavaScript execution in a user's browser. Schneider provides firmware 5.4.13.12 for M241 and M251 via EcoStruxure Machine Expert v2.5.0.1; M258 and LMC058 currently require mitigations. No known public exploitation has been reported.
read more →