The Plone/Zope Security Team disclosed multiple security fixes affecting Plone and related Python components, including a critical remote code execution flaw caused by TALES injection in plone.app.portlets, a sandbox escape in RestrictedPython, and a stored XSS issue tied to MIME type spoofing. The advisory also covered several denial-of-service conditions in Plone features such as iCalendar import, RSS feed portlets, and handling of excessively long titles, descriptions, or filenames, with package-specific guidance issued for supported Plone 6.0, 6.1, and 6.2 deployments and fixes expected in Plone 6.1.5 and 6.2.1 releases.
Separately detailed but included in the same disclosure cycle, the Python icalendar library was found vulnerable to algorithmic-complexity denial of service tracked as CVE-2026-55099. In affected versions 7.1.0, 7.1.1, and 7.1.2, the Component.__eq__ method can take O(2^n) time when comparing attacker-supplied, deeply nested calendar components, allowing a sub-kilobyte malicious .ics file to drive CPU usage for minutes or hang a process if an application performs equality, membership, deduplication, or round-trip comparison on parsed data. Maintainers said parsing alone does not trigger the flaw, and the issue was fixed in icalendar 7.1.3 and 7.2.0 by replacing recursive comparison with a stack-based linear-time traversal.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
The Plone/Zope Security Team announced multiple security fixes for Plone and related components, including the recently disclosed denial-of-service issue in collective/icalendar alongside other vulnerabilities such as TALES injection, sandbox escape, and stored XSS. The announcement said full releases of Plone 6.1.5 and 6.2.1 were expected that week to incorporate the fixes.
Maurits van Rees, on behalf of the Plone/Zope Security Team and the icalendar maintainers, disclosed CVE-2026-55099 on the oss-sec mailing list. The notice said versions 7.1.0, 7.1.1, and 7.1.2 are affected and that the issue is fixed in icalendar 7.1.3 and 7.2.0, while versions before 7.1.0 are unaffected.
A GitHub security advisory disclosed an algorithmic-complexity denial-of-service vulnerability in the Python icalendar library's Component.__eq__ method, where deeply nested calendar components can make equality checks take minutes or hang indefinitely. The advisory described a fix that replaces recursive comparison with an explicit stack-based traversal to restore linear-time behavior.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourceseclists.org
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.