CVE-2026-42990: SQL Server ODBC Driver RCE Flaw

🔴 Critical | Source: Microsoft Security Response Center A heap-based buffer overflow vulnerability in Microsoft’s SQL Server ODBC driver allows an unauthenticated attacker to remotely execute arbitrary code over a network without requiring any user interaction. The flaw is classified as an Elevation of Privilege vulnerability, meaning successful exploitation could grant an attacker significantly elevated permissions on affected systems. Any environment using the SQL Server ODBC driver — including Azure-hosted SQL workloads — should treat this as an urgent patching priority. ...

14 July 2026 Â· ZX Cloud Security

CVE-2026-48561: Microsoft Copilot RCE Vulnerability

🔴 Critical | Source: Microsoft Security Response Center A command injection vulnerability in Microsoft Copilot allows an unauthenticated attacker to execute arbitrary code remotely over a network, without requiring any user interaction or elevated privileges. This is a serious flaw because Copilot is deeply integrated into Microsoft 365 and Azure services, meaning exploitation could give an attacker a foothold across a broad range of enterprise environments. Organisations using Microsoft Copilot should treat this as a priority remediation. ...

14 July 2026 Â· ZX Cloud Security

CVE-2026-49164: AD Domain Services RCE Flaw

🔴 Critical | Source: Microsoft Security Response Center A heap-based buffer overflow vulnerability in Windows Active Directory Domain Services allows an unauthenticated attacker to remotely execute arbitrary code over a network without any user interaction. Active Directory is the backbone of identity and access management in most enterprise Windows environments, meaning a successful exploit could grant an attacker deep control over an organisation’s entire directory infrastructure. This makes it an exceptionally high-impact vulnerability, particularly for hybrid cloud environments where on-premises AD is federated with Azure Active Directory (Entra ID). ...

14 July 2026 Â· ZX Cloud Security

Joomla Extensions CVSSv3 10.0 Flaws Exploited in Wild

🔴 Critical | Source: The Register — Security Attackers are actively exploiting critical vulnerabilities (CVSS 10.0) in two popular Joomla extensions — iCagenda and Balbooa Forms — to compromise websites running the open-source CMS. Joomla powers approximately one million sites worldwide, making the blast radius of these flaws considerable. The perfect severity scores indicate these bugs are trivially exploitable and require no authentication or special privileges. Security Architect’s Take: If your organisation hosts or manages any Joomla-based sites, audit installed extensions immediately and apply patches for iCagenda and Balbooa Forms without delay. Where immediate patching isn’t possible, use a web application firewall (WAF) to block exploit attempts and consider temporarily disabling the affected extensions until remediation is confirmed. ...

14 July 2026 Â· ZX Cloud Security

Russia Blamed for Poland Power Grid Cyberattack

🔴 Critical | Source: The Register — Security The EU and UK have formally attributed a cyberattack on Poland’s power grid to Russian state-sponsored actors, specifically the GRU-linked group Sandworm. The attack, which targeted critical energy infrastructure, had the potential to cut power to approximately half a million people during winter. Sweeping sanctions have been announced against individuals and entities linked to the operation. Security Architect’s Take: Organisations operating or supporting critical national infrastructure should treat this as a prompt to review their OT/IT network segmentation, ensure industrial control systems are air-gapped or strictly access-controlled, and validate that incident response playbooks explicitly cover state-sponsored threat scenarios including destructive malware targeting energy systems. ...

13 July 2026 Â· ZX Cloud Security

Joomla Zero-Days: iCagenda & Balbooa CVSS 10.0 Flaws

🔴 Critical | Source: The Hacker News Two Joomla extensions — iCagenda and Balbooa Forms — have been assigned maximum CVSS scores of 10.0 and confirmed as actively exploited zero-days, prompting CISA to add them to its Known Exploited Vulnerabilities catalogue. These flaws affect widely used Joomla plugins, meaning any organisation running affected versions faces immediate, critical risk. Zero-day status indicates attackers were exploiting these vulnerabilities before patches were available. Security Architect’s Take: Audit all Joomla deployments in your estate immediately and identify any instances running iCagenda or Balbooa Forms extensions; apply vendor patches or remove the extensions without delay. If patching is not immediately possible, consider taking affected Joomla sites offline or placing them behind a WAF with virtual patching rules targeting these CVEs. ...

13 July 2026 Â· ZX Cloud Security

CVE-2008-4128: Cisco IOS CSRF Exploit Alert

🔴 Critical | Source: CISA Known Exploited Vulnerabilities A vulnerability in Cisco IOS 12.4 allows remote attackers to perform cross-site request forgery (CSRF) attacks, tricking authenticated users into executing arbitrary commands on the router via specially crafted URLs. This can result in full device compromise at privilege level 15, the highest administrative tier. Despite its age, CISA has confirmed active exploitation, making remediation urgent. Security Architect’s Take: Audit your estate for any Cisco IOS 12.4 devices — particularly those with HTTP/HTTPS management interfaces exposed — and disable the web-based management interface immediately where not required. Apply available patches or upgrade IOS versions, and enforce network-level controls to restrict management plane access to trusted IP ranges only. ...

13 July 2026 Â· ZX Cloud Security

jscrambler 8.14.0 npm Supply Chain Attack: Infostealer

🔴 Critical | Source: The Hacker News The jscrambler npm package version 8.14.0 was compromised and contained a malicious preinstall hook that automatically downloaded and executed a Rust-based infostealer on Windows, macOS, and Linux. Any developer or CI/CD pipeline that ran ’npm install’ with this version was immediately exposed without any further interaction required. Socket detected the malicious release within six minutes of publication, but the window of exposure remains a concern for any environment that pulled the package during that period. ...

11 July 2026 Â· ZX Cloud Security

Critical Zimbra XSS Flaw Allows Code Execution via Email

🔴 Critical | Source: The Hacker News A critical stored cross-site scripting (XSS) vulnerability in Zimbra’s Classic Web Client allows attackers to embed malicious scripts inside specially crafted emails, which then execute within the victim’s browser session when the email is viewed. No CVE identifier has been assigned yet, but Zimbra has issued updates and is urging immediate patching. The flaw is particularly dangerous because exploitation requires nothing more than a target opening a malicious email. ...

11 July 2026 Â· ZX Cloud Security

Progress ShareFile Storage Zone Controller Shutdown Alert

🔴 Critical | Source: The Hacker News Progress Software has issued an urgent directive to ShareFile customers to shut down their on-premises Storage Zone Controller Windows servers in response to a credible, unspecified external security threat. The company has proactively disabled access to affected accounts whilst it investigates. The nature of the threat has not been publicly disclosed, but the severity of the response suggests a potentially serious vulnerability or active exploitation. ...

10 July 2026 Â· ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options