Zimbra Collaboration Suite · Microsoft Edge · RSFiles extension for Joomla
DAILY THREAT INTELLIGENCE BRIEFING Date: 2026-07-12 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership
EXECUTIVE SUMMARY
Today’s most significant new developments are a compromised jscrambler npm package (version 8.14.0) that executes a Rust-based infostealer on install across all platforms, a critical stored XSS in Zimbra Classic Web Client enabling arbitrary code execution via crafted emails, and an Australian government alert about a global exploitation campaign targeting vulnerable CMS platforms and plugins. Microsoft Edge received a patch for a network-exploitable deserialization RCE. Multiple critical vulnerabilities in the PraisonAI framework and Joomla extensions were also published.
CRITICAL VULNERABILITIES
NEW
Zimbra Classic Web Client — Stored XSS / Arbitrary Code Execution (CVE pending)
- Affected products: Zimbra Collaboration Suite, Classic Web Client (all unpatched versions)
- Severity: Critical (CVE not yet assigned)
- EPSS: Not yet scored
- Technical detail: A stored cross-site scripting vulnerability in the Classic Web Client allows a remote attacker to deliver a specially crafted email that executes arbitrary JavaScript in the recipient’s authenticated session. Successful exploitation can result in session hijacking, credential theft, or further code execution within the user’s browser context. No user interaction beyond opening the malicious email is required, making this a high-value phishing-free initial access vector against organizations using Zimbra on-premises deployments. Zimbra has issued an urgent advisory urging immediate patching.
- Exploitation status: No confirmed in-the-wild exploitation reported; vendor urgency and attack simplicity elevate risk significantly.
- Remediation: Apply Zimbra vendor updates immediately. As an interim measure, consider disabling the Classic Web Client and directing users to the modern interface. Monitor mail gateway logs for anomalous inbound messages with embedded script content.
CVE-2026-58281 (Microsoft Edge — Chromium-based)
- Affected products: Microsoft Edge (Chromium-based) versions prior to 150.0.4078.48
- Severity: High (CVSS 8.3)
- EPSS: Not yet scored
- Technical detail: A deserialization of untrusted data vulnerability allows an unauthenticated remote attacker to execute code over a network. The Chromium-based attack surface means this affects all platforms running Edge. Deserialization flaws in browser engines can be triggered via crafted web content or network-delivered payloads, and the network-exploitable nature removes the requirement for local access.
- Exploitation status: No confirmed exploitation; network-exploitable RCE in a widely deployed browser warrants prompt action.
- Remediation: Update Microsoft Edge to version 150.0.4078.48 or later. Ensure auto-update is enabled across the enterprise. Verify update deployment via endpoint management tooling.
CVE-2026-57827 (RSFiles — Joomla extension)
- Affected products: RSFiles extension for Joomla, versions 1.0 through 1.17.11
- Severity: Critical (CVSS 10.0)
- EPSS: Not yet scored
- Technical detail: An unauthenticated arbitrary file upload vulnerability allows attackers to upload executable files (e.g., PHP webshells) to the web server without any authentication. Successful exploitation results in full remote code execution. The unauthenticated attack vector and CVSS 10.0 score place this in the same risk tier as the Balbooa Forms and iCagenda vulnerabilities reported yesterday. Internet-facing Joomla installations with RSFiles installed are immediately at risk. The companion CVE-2026-57828 (Phoca Download, CVSS 9.0) requires authenticated access as a registered user but similarly leads to RCE via executable file upload.
- Exploitation status: No confirmed exploitation; CVSS 10.0 and trivial attack path make exploitation likely in the near term given the active CMS exploitation campaign (see Active Threats).
- Remediation: Update RSFiles to a version beyond 1.17.11 immediately. Update Phoca Download beyond 6.1.2. Audit web roots for recently uploaded PHP or executable files. Consider temporarily disabling both extensions if patching cannot be completed immediately.
CVE-2026-61447 (PraisonAI — CodeAgent RCE)
- Affected products: PraisonAI before 1.6.78
- Severity: Critical (CVSS 10.0)
- EPSS: Not yet scored
- Technical detail: The CodeAgent._execute_python() function executes LLM-generated Python code without AST validation, import restrictions, or sandboxing. An attacker who can influence LLM outputs — via prompt injection, malicious tool inputs, or direct API access — can achieve arbitrary code execution on the host running PraisonAI. Multiple additional critical and high-severity vulnerabilities were published simultaneously for PraisonAI: CVE-2026-61445 (CVSS 9.4, arbitrary file write and command execution in AICoder), CVE-2026-60090 (CVSS 9.3, SQL injection via unvalidated dimension argument), CVE-2026-61429 (CVSS 8.4, SSRF via DNS rebinding in Crawl4AI backend), CVE-2026-61426 (CVSS 8.8, insecure default binding with no API key and wildcard CORS), and CVE-2026-61439 (CVSS 8.7, prompt injection defense misconfiguration). The breadth of findings suggests a systemic security review was conducted; treat the entire PraisonAI deployment as untrusted until fully patched.
- Exploitation status: No confirmed exploitation; CVSS 10.0 with multiple co-published critical flaws elevates urgency.
- Remediation: Upgrade PraisonAI to 1.6.78 (for 1.x branch) and 4.6.78 (for 4.x branch) and praisonai-platform to 0.1.9. Isolate PraisonAI instances from the internet. Audit API key configurations and CORS settings post-upgrade.
CVE-2026-15155 (Essential Addons for Elementor — WordPress)
- Affected products: Essential Addons for Elementor, versions up to and including 6.6.10
- Severity: High (CVSS 8.8)
- EPSS: 0.37
- Technical detail: An email header injection vulnerability in the authentication flow allows an authenticated attacker to perform account takeover. This is particularly dangerous in multi-tenant WordPress environments where subscriber-level accounts are common. Essential Addons for Elementor is one of the most widely installed WordPress plugins globally, making the attack surface extremely broad. The EPSS score of 0.37 reflects meaningful exploitation probability given the plugin’s install base.
- Exploitation status: No confirmed exploitation; high install base and account takeover impact warrant priority patching.
- Remediation: Update Essential Addons for Elementor beyond version 6.6.10 immediately. Review WordPress admin accounts for unauthorized privilege changes. Given the active global CMS exploitation campaign, treat all WordPress plugin updates as urgent.
ONGOING
- CVE-2026-56291 (Balbooa Forms / Joomla): actively exploited, CISA deadline 2026-07-13 — patch immediately if not already done.
- CVE-2026-48939 (iCagenda / Joomla): actively exploited, CISA deadline 2026-07-13 — patch immediately if not already done.
- CVE-2026-41264 (Flowise): public Metasploit module available; upgrade beyond 3.0.13 urgently.
- CVE-2026-59792 (JetBrains IntelliJ IDEA): update to 2026.1.4 or 2026.2; patch TeamCity (CVE-2026-59793) to 2026.1.2.
- CVE-2026-54088 (filebrowser, EPSS 0.53): upgrade to 2.63.6; restrict network access.
- CVE-2026-52778 (YesWiki, CVSS 9.8, EPSS 0.56): upgrade to 4.6.6.
- CVE-2026-54782 (CoreWCF, CVSS 10.0): upgrade to 1.8.1 or 1.9.1.
- CVE-2026-48282 / CVE-2026-48316 (Adobe ColdFusion): actively exploited; patch or isolate.
- CVE-2026-55255 (Langflow): actively exploited; patch immediately.
- CVE-2026-8037 (Progress Kemp LoadMaster): actively exploited; patch or isolate.
- CVE-2026-46817 (Oracle E-Business Suite): actively exploited; patch immediately.
EUROPEAN ADVISORIES
No new BSI WID or CERT-EU advisories were published in the last 24 hours.
Heise Security published a commentary on 2026-07-11 regarding proposed German intelligence law reforms that would legally compel the BSI to supply zero-day vulnerabilities to the BND and Verfassungsschutz. The commentary argues this would fundamentally compromise the BSI’s defensive mandate and create structural conflicts of interest in Germany’s national cybersecurity posture. This is a policy development, not an operational advisory, but security leadership in German organizations should monitor legislative progress as it may affect BSI’s role as a trusted advisory body.
The Zimbra stored XSS advisory (see Critical Vulnerabilities) has direct relevance to European organizations, as Zimbra on-premises deployments remain common across German public sector and mid-market enterprise environments. No BSI advisory has been published at time of writing; one is anticipated.
ACTIVE THREATS AND CAMPAIGNS
NEW — jscrambler npm Supply Chain Compromise The jscrambler npm package version 8.14.0, published on 2026-07-11, was found to contain a malicious preinstall hook that drops and executes a native Rust-based infostealer binary targeting Windows, macOS, and Linux. Socket detected the compromise six minutes after publication. Any developer or CI/CD pipeline that ran npm install between publication and takedown should be treated as potentially compromised. Immediate actions: audit npm install logs for jscrambler 8.14.0, rotate all secrets and credentials accessible from affected build environments, and scan developer workstations for infostealer indicators.
NEW — Global CMS Exploitation Campaign (ACSC Alert) The Australian Cyber Security Centre issued an alert on 2026-07-11 warning of a global campaign actively exploiting vulnerable CMS platforms and plugins. The campaign aligns with the multiple critical Joomla and WordPress vulnerabilities published this cycle (RSFiles CVE-2026-57827, Phoca Download CVE-2026-57828, Essential Addons CVE-2026-15155, and others). Organizations running public-facing CMS installations should treat all unpatched plugin vulnerabilities as actively targeted. Audit web roots for webshells, review access logs for exploitation patterns, and prioritize CMS plugin patching.
NEW — Ghostcommit Prompt Injection via Image Files Researchers disclosed a technique dubbed “Ghostcommit” that embeds prompt injection payloads inside PNG image files to manipulate AI coding agents. The technique bypassed AI code review tools CodeRabbit and Bugbot and successfully convinced a coding agent to exfiltrate repository secrets (.env file contents) by encoding them as numbers in committed code. Organizations using AI-assisted code review or coding agents should treat this as a credible insider-equivalent threat and implement secret scanning on all commits regardless of AI review status.
ONGOING — Balochistan Police Portal espionage campaign: suspected China- and India-aligned actors targeting Pakistani law enforcement; no direct European relevance confirmed. ONGOING — The Gentlemen ransomware affiliate operation: review Unit 42 IOCs; update detection rules. ONGOING — WP-SHELLSTORM WordPress mass backdooring: audit WordPress installations for unauthorized plugins and PHP files. ONGOING — Progress ShareFile Storage Zone Controllers: shutdown directive remains in effect; no CVE published; monitor for updates. ONGOING — Gitea Docker authentication bypass: apply image updates; audit admin accounts. ONGOING — Helix vishing / Forg365 AiTM targeting Microsoft 365: enforce phishing-resistant MFA; monitor Conditional Access.
SECURITY NEWS AND CONTEXT
Wireshark 4.6.7 was released on 2026-07-11, fixing 12 vulnerabilities and 16 bugs. Organizations using Wireshark for network analysis should update to 4.6.7.
A former ransomware negotiator was sentenced to 70 months for conspiring with BlackCat operators; a Ryuk member separately pleaded guilty facing up to 15 years, reflecting continued law enforcement pressure on ransomware ecosystems. No new operational threat indicators arise from these developments.
RECOMMENDED ACTIONS
- Apply Zimbra updates immediately to address the critical stored XSS in Classic Web Client; consider disabling Classic Web Client as an interim measure and monitor for anomalous inbound mail.
- Update Microsoft Edge to 150.0.4078.48 or later (CVE-2026-58281); verify deployment via endpoint management.
- Update or disable RSFiles (CVE-2026-57827) and Phoca Download (CVE-2026-57828) Joomla extensions; audit web roots for uploaded executables.
- Upgrade PraisonAI to 1.6.78 / 4.6.78 and praisonai-platform to 0.1.9 (CVE-2026-61447 and co-published flaws); isolate from internet and audit API key and CORS configurations.
- Update Essential Addons for Elementor beyond 6.6.10 (CVE-2026-15155); review WordPress admin accounts for unauthorized privilege changes.
- Audit all CI/CD pipelines and developer workstations for jscrambler 8.14.0 npm package installation; rotate all secrets from affected environments immediately.
- Treat all public-facing CMS plugin vulnerabilities as actively targeted per ACSC alert; prioritize patching and conduct web root audits for webshells.
- Implement commit-level secret scanning independent of AI code review tools to mitigate Ghostcommit-style prompt injection attacks.
- Update Wireshark to 4.6.7 on analyst and network engineering workstations.
- Continue remediation of previously reported items: Balbooa Forms CVE-2026-56291 and iCagenda CVE-2026-48939 (CISA deadline 2026-07-13), Flowise CVE-2026-41264, Langflow CVE-2026-55255, ColdFusion CVE-2026-48282/48316, Kemp LoadMaster CVE-2026-8037, Oracle EBS CVE-2026-46817, CoreWCF CVE-2026-54782, YesWiki CVE-2026-52778.