5 new critical disclosures — review patch status on exposed services.
Top threats today
Three highest-priority changes — analyst brief, not a CVE dump.
Critical active threat
CVE-2025-27915Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting
Actively exploited (CISA KEV)
Listed on CISA KEV
Synacor Zimbra Collaboration Suite (ZCS) XSS is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.
Zte Zxhn H108n R1a Firmware: EPSS 17% → 35% · rising (+18%) — EPSS is climbing faster than peer CVEs in this window, a leading indicator even before KEV or public exploit linkage.