CVE-2026-25089: Fortinet FortiSandbox RCE Flaw

🔴 Critical | Source: CISA Known Exploited Vulnerabilities A critical OS command injection vulnerability in Fortinet FortiSandbox (including its cloud and PaaS variants) allows an unauthenticated attacker to run arbitrary commands simply by sending crafted HTTP requests — no login required. This is actively being exploited in the wild, as confirmed by CISA’s addition to its Known Exploited Vulnerabilities catalogue. The potential impact is severe, as FortiSandbox is a security control itself, meaning compromise could blind an organisation to other threats. ...

16 July 2026 Â· ZX Cloud Security

CVE-2026-39808: Fortinet FortiSandbox RCE Flaw

🔴 Critical | Source: CISA Known Exploited Vulnerabilities A critical OS command injection vulnerability in Fortinet FortiSandbox allows an unauthenticated attacker to execute arbitrary commands on the affected system by sending specially crafted HTTP requests. This requires no prior authentication, significantly lowering the bar for exploitation. CISA has confirmed active exploitation in the wild, making immediate remediation essential. Security Architect’s Take: Audit your estate for any internet-exposed FortiSandbox instances and apply Fortinet’s patch immediately — CISA’s remediation deadline is 19 July 2026. As an interim measure, restrict management interface access to trusted IP ranges via network ACLs or firewall rules to reduce the attack surface. ...

16 July 2026 Â· ZX Cloud Security

CVE-2026-58644: Microsoft SharePoint RCE Flaw

🔴 Critical | Source: CISA Known Exploited Vulnerabilities A critical vulnerability in Microsoft SharePoint allows attackers to execute arbitrary code remotely by exploiting unsafe handling of untrusted data during deserialization. This flaw requires no authentication, meaning an attacker with network access could compromise a SharePoint server without any credentials. It is actively being exploited in the wild, making immediate patching essential. Security Architect’s Take: Prioritise applying Microsoft’s patch before the CISA remediation deadline of 19 July 2026; in the interim, restrict network access to SharePoint instances at the perimeter and review audit logs for anomalous deserialization activity or unexpected process spawning from SharePoint worker processes. ...

16 July 2026 Â· ZX Cloud Security

Firefox CVE-2026-15718 & CVE-2026-15719: Critical Patches

🔴 Critical | Source: The Hacker News Mozilla has released emergency patches for Firefox addressing two critical vulnerabilities — CVE-2026-15718 (an invalid pointer in the WebAssembly engine) and CVE-2026-15719 (a site isolation bypass in DOM navigation) — with exploit code already publicly available. Alongside Firefox, updates for Chrome, Adobe, and VMware are also included in this patch cycle, addressing multiple critical flaws across widely deployed software. The public availability of exploit code significantly raises the risk of active exploitation in the near term. ...

15 July 2026 Â· ZX Cloud Security

SonicWall SMA 1000 Zero-Days CVE-2026-15409 Exploited

🔴 Critical | Source: The Hacker News SonicWall has disclosed two actively exploited zero-day vulnerabilities in its SMA 1000 series remote access appliances. The most severe, CVE-2026-15409, carries a maximum CVSS score of 10.0 and allows unauthenticated remote attackers to execute arbitrary commands via a server-side request forgery flaw. Both vulnerabilities are already being exploited in the wild, making this an urgent patching priority for any organisation relying on SMA 1000 devices for remote access. ...

15 July 2026 Â· ZX Cloud Security

CVE-2023-4346: KNX Protocol Device Lockout Flaw

🔴 Critical | Source: CISA Known Exploited Vulnerabilities CVE-2023-4346 affects the KNX building automation protocol, where a flaw in Connection Authorization Option 1 allows an attacker to wipe all devices on a KNX installation and set a BCU key to permanently lock them out — without needing any additional security credentials. This is a known-exploited vulnerability, meaning it has been actively used in real-world attacks. Buildings using KNX-based smart systems for lighting, HVAC, and access control may be at risk of operational disruption or physical security compromise. ...

15 July 2026 Â· ZX Cloud Security

CVE-2026-46817: Oracle E-Business Suite Payments Flaw

🔴 Critical | Source: CISA Known Exploited Vulnerabilities A critical vulnerability in Oracle E-Business Suite allows an unauthenticated attacker with network access over HTTP to fully compromise Oracle Payments, potentially taking complete control of the payment processing component. The flaw stems from improper privilege management, meaning no credentials are required to exploit it. This vulnerability is confirmed as actively exploited in the wild, making prompt remediation urgent. Security Architect’s Take: Immediately restrict network access to Oracle E-Business Suite HTTP endpoints at the perimeter and WAF level, prioritising isolation of the Oracle Payments module. Apply Oracle’s patch before the CISA remediation deadline of 18 July 2026, and audit access logs for any anomalous unauthenticated HTTP activity against the Payments component. ...

15 July 2026 Â· ZX Cloud Security

Microsoft Patch Tuesday: 622 CVEs Fixed July 2026

🔴 Critical | Source: The Register — Security Microsoft’s July 2026 Patch Tuesday has released fixes for a staggering 622 CVEs, more than tripling the previous month’s record-breaking 206. The sheer volume signals either a significant backlog being cleared or a dramatic increase in vulnerability discovery across Microsoft’s product estate. For security teams, this represents an enormous patching burden that demands careful prioritisation. Security Architect’s Take: Immediately triage the 622 CVEs by severity and exploitability, focusing first on any Remote Code Execution or Privilege Escalation vulnerabilities affecting Azure, Windows Server, and identity services. Use Microsoft’s Exploitability Index and cross-reference with CISA’s KEV catalogue to drive your patching order, and consider accelerating deployment pipelines for critical cloud-hosted workloads. ...

14 July 2026 Â· ZX Cloud Security

Microsoft Patches 622 Flaws & Two Zero-Days July 2025

🔴 Critical | Source: The Hacker News Microsoft’s July 2025 Patch Tuesday is the largest on record, addressing 622 CVEs — more than triple the previous monthly high. Two of those vulnerabilities are zero-days already being actively exploited in the wild, making immediate prioritisation essential. The sheer scale of this release significantly increases the attack surface for any organisation running Microsoft or Azure-dependent workloads. Security Architect’s Take: Prioritise the two actively exploited zero-days immediately — identify affected systems via Microsoft’s Security Update Guide and expedite patching through your change management process outside the normal cycle if necessary. Given the record volume of fixes, triage the remaining CVEs by CVSS score and exposure, focusing on internet-facing and identity-related components first. ...

14 July 2026 Â· ZX Cloud Security

CVE-2026-44747: SAP NetWeaver ABAP CVSS 9.9 Flaw Patched

🔴 Critical | Source: The Hacker News SAP has issued a critical patch for CVE-2026-44747, a CVSS 9.9 out-of-bounds write vulnerability in SAP NetWeaver Application Server ABAP. The flaw allows an authenticated attacker to corrupt memory through logical errors in memory management, potentially exposing or modifying sensitive data. Given NetWeaver ABAP’s widespread use as a core enterprise application platform, the blast radius for unpatched systems is substantial. Security Architect’s Take: Prioritise patching SAP NetWeaver ABAP instances immediately as part of an emergency change — a CVSS 9.9 with authenticated access as the only barrier is highly exploitable in environments with broad internal user bases or compromised accounts. Review SAP Security Note for CVE-2026-44747, confirm patch deployment across all landscapes (development, QA, production), and validate that SAP systems are not directly internet-exposed without a WAF or SAP Web Dispatcher. ...

14 July 2026 Â· ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options