CVE-2026-60137: WordPress Core SQL Injection & RCE

🔴 Critical | Source: CISA Known Exploited Vulnerabilities A SQL injection vulnerability in WordPress Core allows malicious input passed by a plugin or theme to compromise the database layer. When chained with CVE-2026-63030, an unauthenticated attacker can achieve remote code execution on default WordPress installations with no prior access required. This is actively exploited in the wild and carries a CISA remediation deadline of 4 August 2026. Security Architect’s Take: Patch WordPress Core immediately and audit all third-party plugins and themes for untrusted input handling; consider placing WordPress instances behind a WAF with SQL injection and RCE rules enabled, and restrict outbound network access from web servers to limit post-exploitation blast radius. ...

21 July 2026 Â· ZX Cloud Security

CVE-2026-63030: WordPress SQL Injection & RCE Flaw

🔴 Critical | Source: CISA Known Exploited Vulnerabilities A critical vulnerability in WordPress Core allows attackers to perform SQL Injection, potentially leading to full Remote Code Execution on affected sites. The flaw stems from an interpretation conflict and is actively being exploited in the wild, as confirmed by CISA’s Known Exploited Vulnerabilities catalogue. It can be chained with a second vulnerability (CVE-2026-60137) to amplify impact. Security Architect’s Take: Patch WordPress Core immediately to the remediated version — the CISA-mandated deadline of 24 July 2026 applies to federal agencies but should be treated as urgent for all environments. Audit any cloud-hosted WordPress deployments (e.g. on AWS, Azure, or GCP via managed app services or self-hosted VMs) and ensure WAF rules are in place to block SQL injection attempts while patching is underway. ...

21 July 2026 Â· ZX Cloud Security

Critical WordPress Vulnerability Exploited in the Wild

🔴 Critical | Source: The Register — Security A critical vulnerability in WordPress is being actively exploited in the wild, with attackers leveraging it to cause a range of malicious outcomes including site takeovers and malware injection. Dozens of proof-of-concept exploits have been published publicly, significantly lowering the bar for less skilled attackers. The combination of active exploitation and widespread PoC availability makes this an urgent patching priority for any organisation running WordPress. ...

20 July 2026 Â· ZX Cloud Security

CVE-2026-42533: Critical NGINX RCE & Crash Flaw

🔴 Critical | Source: The Hacker News A critical heap buffer overflow vulnerability in NGINX (CVE-2026-42533) allows an unauthenticated remote attacker to crash worker processes or potentially execute arbitrary code by sending crafted HTTP requests. F5 patched the flaw on 15 July 2026 in NGINX stable (1.30.4), mainline (1.31.3), and NGINX Plus (37.0.3.1). Given NGINX’s ubiquity as a web server and reverse proxy across cloud-hosted infrastructure, the blast radius is significant. ...

19 July 2026 Â· ZX Cloud Security

SonicWall SMA 1000 Zero-Days Exploited for Root Access

🔴 Critical | Source: The Hacker News A previously unknown threat actor, tracked as UTA0533, exploited zero-day vulnerabilities in SonicWall SMA 1000 series VPN appliances to gain root-level access before the flaws were publicly disclosed. Exploitation is believed to have begun as early as 22 June 2026, discovered during an incident response investigation by Volexity. This is significant because VPN appliances sit at the network perimeter and root access means full device compromise, potentially exposing internal corporate networks. ...

19 July 2026 Â· ZX Cloud Security

wp2shell WordPress RCE Flaw: Patch to 6.9.5 or 7.0.2 Now

🔴 Critical | Source: The Hacker News A critical unauthenticated remote code execution vulnerability, dubbed wp2shell, exists in WordPress core versions 6.9 and 7.0, meaning any site running a default installation — with no plugins — could be fully compromised via a single anonymous HTTP request. WordPress has patched the flaw in versions 6.9.5 and 7.0.2 and has pushed forced auto-updates to affected sites. The vulnerability was discovered by Adam Kues at Assetnote, the attack surface management arm of Searchlight Cyber. ...

17 July 2026 Â· ZX Cloud Security

FortiSandbox Command Injection Flaws Actively Exploited

🔴 Critical | Source: The Register — Security Critical command injection vulnerabilities in Fortinet’s FortiSandbox product are being actively exploited by attackers, prompting CISA to issue a mandatory patch order. FortiSandbox is used by organisations to analyse potentially malicious files and URLs in an isolated environment. Active exploitation means unpatched systems are at immediate risk of compromise, potentially allowing attackers to execute arbitrary commands on the underlying host. Security Architect’s Take: Prioritise patching FortiSandbox instances immediately, particularly any internet-exposed or perimeter-adjacent deployments — CISA’s order applies to US federal agencies but the active exploitation makes this urgent for all organisations. Review firewall rules to restrict management interface access to trusted IPs only while patches are applied. ...

17 July 2026 Â· ZX Cloud Security

CVE-2026-58644: SharePoint RCE Zero-Day Added to CISA KEV

🔴 Critical | Source: The Hacker News A critical zero-day vulnerability (CVE-2026-58644, CVSS 9.8) in Microsoft SharePoint Server allows remote code execution via a deserialization flaw and is already being actively exploited in the wild. CISA has added it to its Known Exploited Vulnerabilities catalogue, mandating that US federal agencies patch by 19 July 2026. Given SharePoint’s widespread use as a collaboration platform, the blast radius for unpatched organisations is significant. ...

17 July 2026 Â· ZX Cloud Security

CVE-2026-59117 Windows Terminal RCE Vulnerability

🔴 Critical | Source: Microsoft Security Response Center CVE-2026-59117 is a remote code execution vulnerability in Windows Terminal caused by an integer overflow flaw, meaning an attacker on a network could potentially run malicious code on an affected system without needing valid credentials. This is particularly concerning in cloud and enterprise environments where Windows Terminal is commonly used by engineers and administrators to manage Azure resources. If exploited, an attacker could gain a foothold on a privileged workstation, potentially escalating access to connected cloud infrastructure. ...

16 July 2026 Â· ZX Cloud Security

CVE-2026-53412: Critical Zoom Windows Flaw Patched

🔴 Critical | Source: The Hacker News Zoom has patched a critical vulnerability (CVE-2026-53412, CVSS 9.8) in its Windows Desktop Client, VDI Client, and Meeting SDK caused by improper input validation. The flaw could allow an attacker to take over a victim’s Zoom account without requiring authentication. Given the near-maximum CVSS score and the widespread enterprise use of Zoom, the potential blast radius is significant. Security Architect’s Take: Prioritise patching Zoom Desktop Client, VDI Client, and Meeting SDK for Windows across your estate immediately — a CVSS 9.8 with account takeover potential warrants emergency change procedures. Ensure your software inventory and endpoint management tooling (e.g. Intune, SCCM) can confirm patched version deployment, and consider restricting Zoom VDI Client access until remediation is confirmed in high-sensitivity environments. ...

16 July 2026 Â· ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options