CVE-2026-57984: Microsoft Edge RCE Vulnerability

🔴 Critical | Source: Microsoft Security Response Center A use-after-free memory vulnerability in Microsoft Edge (Chromium-based) allows a remote, unauthenticated attacker to execute arbitrary code on a victim’s machine over a network. Use-after-free bugs occur when a programme continues to reference memory after it has been freed, which attackers can exploit to hijack execution flow. This is particularly dangerous in a browser context, where visiting a malicious web page or clicking a crafted link could be sufficient to trigger exploitation. ...

3 July 2026 · ZX Cloud Security

CVE-2026-57988: Microsoft Edge RCE Vulnerability

🔴 Critical | Source: Microsoft Security Response Center CVE-2026-57988 is a remote code execution vulnerability in Microsoft Edge (Chromium-based) caused by a relative path traversal flaw. An unauthenticated attacker could exploit this over a network to execute arbitrary code on a victim’s machine. This is particularly concerning in enterprise environments where Edge is widely deployed and users may access cloud management portals or internal tooling through the browser. Security Architect’s Take: Prioritise pushing the patched Edge update across your estate via Intune or your endpoint management tooling immediately, and consider temporarily restricting access to sensitive cloud console URLs (Azure Portal, AWS Console) from unmanaged or unpatched devices using Conditional Access or browser-based device compliance policies. ...

3 July 2026 · ZX Cloud Security

CVE-2026-57992: Microsoft Edge RCE Vulnerability

🔴 Critical | Source: Microsoft Security Response Center CVE-2026-57992 is a use-after-free vulnerability in Microsoft Edge (Chromium-based) that allows an unauthenticated attacker to execute arbitrary code remotely. Use-after-free bugs occur when a programme continues to use memory after it has been freed, which attackers can exploit to hijack execution flow. This is particularly concerning for organisations where Edge is used to access cloud management portals, as a successful exploit could compromise user sessions and credentials. ...

3 July 2026 · ZX Cloud Security

Citrix Bleed 2 CVE-2025-5777 Exploited by Anubis Ransomware

🔴 Critical | Source: The Hacker News The Anubis ransomware group is actively exploiting CVE-2025-5777, dubbed Citrix Bleed 2, to gain initial access to target environments. Affiliates are combining this with Bring Your Own Vulnerable Driver (BYOVD) techniques, supply chain credential theft, and legitimate remote management tooling to move laterally and evade detection. The breadth of tactics across multiple affiliates makes this a significant and evolving threat to enterprise environments running Citrix NetScaler. ...

2 July 2026 · ZX Cloud Security

SharePoint RCE Added to CISA KEV — Patch Now

🔴 Critical | Source: The Register — Security A remote code execution vulnerability in Microsoft SharePoint on-premises servers has been added to CISA’s Known Exploited Vulnerabilities catalogue, meaning it is actively being used in real-world attacks. Exploitation requires only a valid SharePoint account, making the barrier to attack unusually low. Microsoft had previously assessed exploitation as ’less likely’, but CISA’s addition signals that assessment was incorrect and patching is now urgent. ...

2 July 2026 · ZX Cloud Security

Oracle E-Business Suite Exploited Before PoC Release

🔴 Critical | Source: The Register — Security Attackers were actively exploiting a critical vulnerability in Oracle E-Business Suite before public proof-of-concept exploit code was released, suggesting they reverse-engineered Oracle’s own patch to identify and weaponise the flaw. This technique, known as patch-diffing, allows sophisticated threat actors to gain a significant head start over defenders. The incident highlights the narrow and shrinking window organisations have to apply patches before they face active exploitation. ...

2 July 2026 · ZX Cloud Security

AI Agent Uses Langflow RCE for Autonomous Ransomware

🔴 Critical | Source: The Hacker News Security researchers at Sysdig have identified what they believe is the first fully autonomous ransomware attack orchestrated end-to-end by an AI agent, tracked as JADEPUFFER. The attacker exploited a remote code execution vulnerability in Langflow, an open-source AI workflow tool, allowing a large language model to independently handle intrusion, credential theft, lateral movement, and database encryption. This marks a significant escalation in threat sophistication, as AI removes the need for a skilled human operator to manage each attack stage. ...

2 July 2026 · ZX Cloud Security

FortiBleed Linked to INC & Lynx Ransomware Groups

🔴 Critical | Source: The Hacker News A large-scale credential theft campaign targeting Fortinet FortiGate devices, dubbed ‘FortiBleed’, has been directly linked to the INC and Lynx ransomware groups. Stolen credentials are being harvested and fed into ransomware deployment pipelines, with one operator confirmed to be managing negotiation panels for both groups simultaneously. This confirms FortiBleed is not opportunistic scanning but a structured, financially motivated operation with ransomware as the end goal. ...

2 July 2026 · ZX Cloud Security

SharePoint RCE CVE-2026-45659: CISA KEV Active Exploit

🔴 Critical | Source: The Hacker News A high-severity remote code execution vulnerability in Microsoft SharePoint Server (CVE-2026-45659, CVSS 8.8) has been added to CISA’s Known Exploited Vulnerabilities catalogue following confirmed active exploitation in the wild. The flaw stems from insecure deserialisation of untrusted data, a class of bug that allows attackers to execute arbitrary code on affected servers. SharePoint’s widespread use in enterprise environments makes this a significant risk for organisations that have not yet patched. ...

2 July 2026 · ZX Cloud Security

Unpatched Argo CD Flaw Risks Kubernetes Takeover

🔴 Critical | Source: The Hacker News A security researcher at Synacktiv has uncovered an unpatched vulnerability in Argo CD’s repo-server component that allows an unauthenticated attacker to execute arbitrary code if they can reach the component’s internal network port. The flaw carries no CVE assignment yet and has no available fix. Successful exploitation could result in a full Kubernetes cluster takeover, making this a significant risk for any organisation using Argo CD in their GitOps pipeline. ...

1 July 2026 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options