Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

1 detection

Detects incoming HTTP POST requests to the Zimbra OnlyOffice document handler containing path traversal sequences (e.g., '..'). This pattern is indicative of an attempt to exploit CVE-2026-93643 by manipulating document save or callback paths to access unauthorized files on the server.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
7 days ago
000