Announcements

TrueConf Server: TrueConf Server Missing Authentication for Critical Function Vulnerability

  • 22nd August 2026
A security flaw has been identified in TrueConf Server, where a critical high-risk function does not require proper authentication to access. This means unapproved users can reach the function without a valid login or permission.An attacker with network access to the server's 4307/TCP port can exploit this flaw to run custom scripts on the server ...
Continue reading

TrueConf Server: TrueConf Server Code Injection Vulnerability

  • 22nd August 2026
A code injection vulnerability has been identified in TrueConf Server, a service some hosting clients run on their accounts. This flaw allows outside actors to send malicious, specially designed input to the server to manipulate its internal operations.An unauthorized remote attacker with network access to your server’s 4307/TCP port could ...
Continue reading

Synacor Zimbra Collaboration Suite (ZCS): Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability

  • 22nd August 2026
A security flaw has been identified in the Zimbra Collaboration Suite (ZCS), a common platform for business email, shared calendars, and team collaboration tools.This is an operating system command injection vulnerability. It can be exploited by an attacker who does not have a valid login to your Zimbra account: they only need to send specially ...
Continue reading

MA-1471.072026: MyCERT Advisory - Microsoft SharePoint Hardening After New Exploitations

  • 22nd August 2026
A security advisory from MyCERT, published on 20 July 2026, addresses new active exploitation of Microsoft SharePoint, a common tool many businesses use for document sharing, team collaboration, and website content management.If your hosted website or business services use Microsoft SharePoint, these active attacks could allow unauthorized users ...
Continue reading