BeyondTrust Auth Bypass CVE-2026-40138 Patched

🔴 Critical | Source: The Hacker News BeyondTrust has patched two critical authentication bypass vulnerabilities in its Remote Support and Privileged Remote Access (PRA) products, including CVE-2026-40138 which carries a CVSS score of 9.2. The flaws can be exploited by unauthenticated attackers, potentially granting full control of affected systems. Given that these products are widely used to manage privileged access to enterprise and cloud infrastructure, the blast radius of a successful exploit is significant. ...

7 July 2026 · ZX Cloud Security

CVE-2026-48282: Adobe ColdFusion Path Traversal RCE

🔴 Critical | Source: CISA Known Exploited Vulnerabilities A path traversal vulnerability in Adobe ColdFusion (CVE-2026-48282) allows attackers to navigate outside restricted directories and execute arbitrary code under the permissions of the currently running user. CISA has added this to its Known Exploited Vulnerabilities catalogue, confirming active exploitation in the wild. ColdFusion is commonly used to serve web applications, meaning a successful attack could lead to full server compromise. Security Architect’s Take: Prioritise patching any internet-facing or internally accessible ColdFusion instances immediately ahead of the 10 July 2026 CISA remediation deadline, and consider placing them behind a web application firewall with path traversal detection rules as an interim compensating control whilst patches are applied. ...

7 July 2026 · ZX Cloud Security

CVE-2026-48908: JoomShaper SP Page Builder RCE Flaw

🔴 Critical | Source: CISA Known Exploited Vulnerabilities A critical vulnerability in the JoomShaper SP Page Builder plugin for Joomla allows unauthenticated attackers to upload arbitrary files, including malicious PHP scripts, which can then be executed on the server. This effectively grants full remote code execution to anyone with network access to the site, requiring no credentials whatsoever. CISA has added this to its Known Exploited Vulnerabilities catalogue, confirming active exploitation in the wild. ...

7 July 2026 · ZX Cloud Security

CVE-2026-55255: Langflow Auth Bypass Exploited

🔴 Critical | Source: CISA Known Exploited Vulnerabilities A vulnerability in Langflow, an open-source tool for building AI-powered workflows, allows an authenticated attacker to execute any other user’s workflow simply by knowing or guessing its ID. This is an authorisation bypass flaw, meaning the application fails to verify that a user actually owns the flow they are requesting to run. Because Langflow is actively exploited in the wild and listed on the CISA KEV catalogue, this is a serious and immediate risk for any organisation running the platform. ...

7 July 2026 · ZX Cloud Security

CVE-2026-56290: Joomlack Page Builder RCE Flaw

🔴 Critical | Source: CISA Known Exploited Vulnerabilities A critical vulnerability in the Joomlack Page Builder plugin allows unauthenticated attackers to upload arbitrary files to a server, which can be exploited to execute malicious code remotely. This is classified as an improper access control flaw, meaning no login or privileges are required to exploit it. CISA has added it to its Known Exploited Vulnerabilities catalogue, confirming active exploitation in the wild. ...

7 July 2026 · ZX Cloud Security

CVE-2026-53359: Linux KVM Guest VM Escape Flaw

🔴 Critical | Source: The Hacker News A 16-year-old use-after-free vulnerability in the Linux KVM hypervisor (CVE-2026-53359), dubbed ‘Januscape’, allows a guest virtual machine to corrupt host kernel memory and potentially escape its isolation boundary. The flaw affects both Intel and AMD x86 systems via shared shadow MMU code. A public proof-of-concept already causes host kernel panics, and the researcher claims a full working exploit exists but has not been released. ...

6 July 2026 · ZX Cloud Security

CVE-2026-20896: Gitea Docker Auth Bypass Exploited

🔴 Critical | Source: The Hacker News A critical vulnerability (CVE-2026-20896, CVSS 9.8) in Gitea Docker images allows unauthenticated attackers to gain elevated privileges by spoofing the X-WEBAUTH-USER HTTP header, which Gitea trusts from any source IP. Active exploitation attempts have been observed just 13 days after public disclosure, indicating rapid uptake by threat actors. Organisations running Gitea in Docker environments are at immediate risk of full account takeover without requiring any credentials. ...

6 July 2026 · ZX Cloud Security

CVE-2026-46242: Bad Epoll Linux Root Exploit

🔴 Critical | Source: The Hacker News A Linux kernel vulnerability dubbed ‘Bad Epoll’ (CVE-2026-46242) allows an unprivileged local user to escalate privileges to root, giving them full control of an affected system. It impacts Linux desktops, servers, and Android devices. A patch has been released, making rapid remediation the immediate priority. Security Architect’s Take: Prioritise patching Linux hosts and Android-based endpoints — particularly cloud workloads running on Linux VMs or containers — to the latest kernel version addressing CVE-2026-46242. Assess your attack surface for any multi-tenant or shared environments where unprivileged user access exists, as local privilege escalation flaws carry the highest risk in those contexts. ...

3 July 2026 · ZX Cloud Security

CVE-2026-56645: Microsoft Edge RCE Vulnerability

🔴 Critical | Source: Microsoft Security Response Center A heap-based buffer overflow vulnerability in Microsoft Edge (Chromium-based) allows an unauthenticated attacker to execute arbitrary code remotely over a network. This type of flaw can be exploited without requiring the victim to take any action beyond having a vulnerable browser version in use. The risk is significant in enterprise environments where Edge is widely deployed, particularly on systems with access to cloud management portals and sensitive resources. ...

3 July 2026 · ZX Cloud Security

CVE-2026-57975: Microsoft Edge RCE Vulnerability

🔴 Critical | Source: Microsoft Security Response Center A type confusion vulnerability in Microsoft Edge (Chromium-based) allows an unauthenticated attacker to execute arbitrary code remotely by exploiting how the browser handles certain resource types. This class of bug is considered high-risk because it can be triggered without user authentication and may require only minimal interaction, such as visiting a malicious webpage. Organisations relying on Edge for cloud console access or web-based tooling face elevated exposure. ...

3 July 2026 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options