High 7.2
KEV + Ransomware
CVE-2022-27925
UAT-10147 uses AI to exploit web servers
Vendor / product: Zimbra, AjaxPro, Nacos, Telerik UI for ASP.NET AJAX, Dirty Pipe, Baron Samedit, Windows IIS, Linux
Event date: 2026-03-15
Public PoC: Yes
First tracked by RiskWire: 2026-08-21
CISA KEV catalog
Added to KEV
Federal remediation due
2022-09-01 (1480 days overdue)
Ransomware campaign use
Known
CISA description
Synacor Zimbra Collaboration Suite (ZCS) contains flaw in the mboximport functionality, allowing an authenticated attacker to upload arbitrary files to perform remote code execution. This vulnerability was chained with CVE-2022-37042 which allows for unauthenticated remote code execution.
Required action
Apply updates per vendor instructions.
Named threat actors
UAT-10147
Sources & citations (3)
- UAT-10147 Compromises Web Servers to Deploy BadIIS for SEO Fraud and Data Theft gbhackers.com · 2026-08-21
- Chinese Hackers Use AI Agents to Exploit Web Servers and Automate Attacks cybersecuritynews.com · 2026-08-21
- UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit thehackernews.com · 2026-08-24
References
See CVE-2022-27925 in context
RiskWire tracks every exploited CVE this week, cross-referenced against CISA KEV with federal remediation deadlines. Filtered to your vendor stack.
Book a 20-min demo →