CVE-2026-16723: Fastjson 1.x RCE Exploited, No Patch

🔴 Critical | Source: The Hacker News A critical remote code execution vulnerability (CVE-2026-16723) in Fastjson 1.x, Alibaba’s widely-used Java JSON library, is being actively exploited in the wild with no patch currently available. Attackers can send a crafted JSON request to vulnerable Spring Boot applications and execute arbitrary code without authentication, inheriting the full privileges of the Java process. The absence of a fix makes this particularly dangerous for any organisation running Fastjson 1.x in production. ...

25 July 2026 · ZX Cloud Security

GitLab RCE PoC: Patch Self-Managed Instances Now

🔴 Critical | Source: The Hacker News A working proof-of-concept exploit has been published for a remote code execution flaw in GitLab, allowing any authenticated user with push access to run arbitrary commands as the ‘git’ system user on unpatched self-managed instances. The vulnerability is triggered by committing a specially crafted Jupyter notebook and viewing its diff, which leaks heap memory and enables code execution. GitLab patched the flaw on 10 June, but any self-managed instance still running version 18.11.3 without the update is directly at risk. ...

25 July 2026 · ZX Cloud Security

Cl0p Exploiting PTC Windchill & FlexPLM RCE Flaws

🔴 Critical | Source: The Hacker News Affiliates of the Cl0p ransomware group are actively exploiting vulnerabilities in PTC Windchill and FlexPLM, two widely used product lifecycle management platforms. Attackers chain a pre-authentication information disclosure flaw in FlexPLM’s WSDL endpoint with a server-side vulnerability in the Windchill login servlet to achieve unauthenticated remote code execution. Any organisation with internet-exposed instances of these products is at immediate risk of data theft and extortion. ...

25 July 2026 · ZX Cloud Security

Certighost: Low-Priv AD Users Can Impersonate Domain Control

🔴 Critical | Source: The Hacker News A working exploit named Certighost allows any low-privileged Active Directory user to obtain a certificate impersonating a Domain Controller, then use that certificate to authenticate as the DC via Kerberos. Because Domain Controllers hold directory replication privileges, an attacker can leverage this to run a DCSync attack and extract the krbtgt password hash, effectively compromising the entire domain. Published exploit code is already publicly available, making this an immediate operational risk. ...

24 July 2026 · ZX Cloud Security

ChatGPT AgentForger Flaw: Rogue AI Agents via Phishing

🔴 Critical | Source: The Hacker News A critical vulnerability dubbed AgentForger, discovered by Zenity Labs in OpenAI’s ChatGPT Workspace Agents, could have allowed an attacker to silently create, authorise, and deploy a rogue AI agent inside a victim’s organisation using nothing more than a phishing link. The flaw required no elevated access beyond tricking a user into clicking a malicious URL, giving attackers a stealthy foothold within enterprise AI workflows. OpenAI patched the issue on 8 June 2026. ...

24 July 2026 · ZX Cloud Security

Bing Images RCE: CVE-2026-32194 SVG Flaw Explained

🔴 Critical | Source: The Hacker News A maliciously crafted SVG file uploaded to Bing Image Search triggered remote code execution on Microsoft’s production image-processing infrastructure, granting attackers SYSTEM-level privileges on Windows workers and root on Linux machines in the same fleet. The vulnerability affected multiple hosts across different network ranges, confirming it was a systemic flaw in Bing’s image-processing tier rather than an isolated misconfiguration. Microsoft has assigned two critical CVEs — CVE-2026-32194 — underscoring the severity of the exposure. ...

24 July 2026 · ZX Cloud Security

Russian APT Exploits Zimbra Zero-Day to Steal Email & 2FA

🔴 Critical | Source: The Hacker News A Russian state-sponsored espionage group exploited an undisclosed zero-day vulnerability in the Zimbra webmail client to silently harvest emails, contact directories, saved browser passwords, and two-factor authentication recovery codes from targeted Western organisations. The attack was triggered simply by opening a malicious message — no further user interaction was required. The NSA, CISA, and partner agencies have since issued a joint advisory disclosing the campaign. ...

23 July 2026 · ZX Cloud Security

CVE-2026-35425: Azure APIM RCE Vulnerability

🔴 Critical | Source: Microsoft Security Response Center A remote code execution vulnerability in Azure API Management (APIM) allows an attacker who already has some level of authorised access to run arbitrary code over the network. Improper access controls are at the root of the flaw, meaning existing authentication is insufficient to contain the blast radius. This is particularly concerning given how widely APIM is used as a gateway to backend services and sensitive APIs. ...

23 July 2026 · ZX Cloud Security

CVE-2026-50517: M365 Copilot RCE Vulnerability

🔴 Critical | Source: Microsoft Security Response Center A remote code execution vulnerability (CVE-2026-50517) has been identified in Microsoft 365 Copilot, caused by insecure handling of untrusted data during deserialization. An attacker who already has authorised access to the service could exploit this flaw to run arbitrary code across the network. Given M365 Copilot’s deep integration with enterprise data and Microsoft 365 services, successful exploitation could have significant downstream impact. Security Architect’s Take: Review your organisation’s M365 Copilot deployment and apply any available Microsoft patches or mitigations immediately. In the interim, assess whether network-level controls or conditional access policies can limit exposure, and audit which accounts hold authorised access to Copilot to reduce the potential attacker surface. ...

23 July 2026 · ZX Cloud Security

CVE-2026-56163: Azure Kubernetes Service Privilege Escalatio

🔴 Critical | Source: Microsoft Security Response Center A vulnerability in Microsoft Azure Kubernetes Service (AKS) allows an unauthenticated attacker to gain elevated privileges over a network by exploiting a missing authentication check on a critical function. This means an attacker without any valid credentials could potentially gain elevated control over Kubernetes workloads or the underlying cluster infrastructure. The network-based attack vector makes this particularly dangerous as it does not require local access to exploit. ...

23 July 2026 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options