Adobe Patches 7 CVSS 10.0 Flaws in ColdFusion & Campaign

🔴 Critical | Source: The Hacker News Adobe has issued emergency patches addressing seven CVSS 10.0 (maximum severity) vulnerabilities across ColdFusion and Campaign Classic. The flaws could allow attackers to execute arbitrary code, escalate privileges, read files from the underlying system, and bypass security controls. Given the maximum severity rating, exploitation could lead to full system compromise with no user interaction required. Security Architect’s Take: Prioritise patching any internet-facing or internally accessible ColdFusion and Campaign Classic instances immediately — CVSS 10.0 scores indicate the highest possible exploitability and impact. Audit your estate for these products, isolate affected servers where patching cannot be applied immediately, and review web application firewall rules to block known exploit patterns while remediation is under way. ...

1 July 2026 Â· ZX Cloud Security

Cursor AI CVE-2026-50548 & 50549: Sandbox Escape

🔴 Critical | Source: The Hacker News Two critical vulnerabilities (CVE-2026-50548 and CVE-2026-50549), collectively named DuneSlide, have been discovered in the Cursor AI code editor. They allow a maliciously crafted prompt to escape the editor’s security sandbox and execute arbitrary commands on the developer’s machine without requiring any user interaction or approval. With CVSS scores of 9.8 and 9.3 respectively, the risk to developer workstations and by extension CI/CD pipelines and cloud environments is significant. ...

1 July 2026 Â· ZX Cloud Security

CVE-2026-8037: Kemp LoadMaster RCE Actively Exploited

🔴 Critical | Source: The Hacker News A critical pre-authentication remote code execution vulnerability (CVE-2026-8037, CVSS 9.6) in Progress Kemp LoadMaster is being actively exploited in the wild. The flaw is an OS command injection issue that attackers can trigger without needing valid credentials, making it particularly dangerous. LoadMaster is a widely used application delivery and load balancing solution, meaning exploitation could expose network infrastructure and backend services. Security Architect’s Take: If you have internet-facing Kemp LoadMaster instances, apply the vendor patch immediately and review access logs for exploitation indicators flagged by eSentire’s TRU advisory. Consider restricting management interface access to trusted IP ranges or placing it behind a VPN as an interim control if patching cannot be completed immediately. ...

1 July 2026 Â· ZX Cloud Security

Langflow RCE CVE-2026-33017 Exploited: Monero Miner

🔴 Critical | Source: The Hacker News A critical unauthenticated remote code execution vulnerability in Langflow (CVE-2026-33017, CVSS 9.3) is being actively exploited by threat actors to install Monero cryptocurrency mining malware on exposed AI application endpoints. Langflow is a popular open-source platform for building AI workflows, and publicly accessible instances are being scanned and compromised at scale. The attack requires no authentication, making any internet-facing deployment an immediate target. Security Architect’s Take: Audit your environment immediately for any internet-exposed Langflow instances and apply the latest patch or take them offline; enforce network-level controls (WAF, security groups, VPC isolation) to ensure Langflow is never directly reachable from the public internet, and implement egress filtering to detect unexpected outbound connections to mining pools. ...

30 June 2026 Â· ZX Cloud Security

SimpleHelp CVE-2026-48558 Exploited: New Malware Deployed

🔴 Critical | Source: The Hacker News Attackers are actively exploiting CVE-2026-48558, a critical authentication bypass flaw (CVSS 10.0) in SimpleHelp remote support software, to deploy two newly discovered malware families: TaskWeaver and Djinn Stealer. The vulnerability resides in the OpenID Connect flow and requires no authentication to exploit, making it trivially accessible to threat actors. This is particularly concerning given SimpleHelp’s widespread use in managed service provider environments, where a single compromised instance can cascade across many downstream clients. ...

30 June 2026 Â· ZX Cloud Security

CVE-2026-8037: Kemp LoadMaster Pre-Auth RCE Flaw

🔴 Critical | Source: The Hacker News A critical unauthenticated remote code execution vulnerability (CVE-2026-8037) in Progress Kemp LoadMaster allows an attacker to run arbitrary commands as root simply by sending a crafted API request — no credentials required. With a CVSS score of 9.8, this is as severe as vulnerabilities get, and any internet-exposed LoadMaster appliance with the API enabled is at immediate risk. A patch has been released and should be applied without delay. ...

30 June 2026 Â· ZX Cloud Security

CVE-2026-46817: Oracle EBS Flaw Exploited in Wild

🔴 Critical | Source: The Hacker News A critical vulnerability in Oracle E-Business Suite’s Payments module (CVE-2026-46817, CVSS 9.8) is being actively exploited in the wild. The flaw allows unauthenticated attackers to abuse improper privilege management to fully compromise affected instances. Active exploitation significantly raises the risk for any organisation running unpatched versions of Oracle EBS. Security Architect’s Take: Audit your Oracle E-Business Suite deployments immediately and apply Oracle’s patch for CVE-2026-46817 as an emergency priority. If patching cannot be completed immediately, consider restricting network access to Oracle Payments endpoints at the perimeter and review audit logs for anomalous privilege escalation activity. ...

30 June 2026 Â· ZX Cloud Security

Anonymous 0-Day Exploitarium Repo: Live Attacks Underway

🔴 Critical | Source: The Register — Security An anonymous researcher has published a public repository containing multiple zero-day exploits, with at least two of the vulnerabilities already being actively exploited in the wild. The release of a ready-to-use ’exploitarium’ significantly lowers the barrier for attackers, putting organisations at elevated risk before patches are available. The lack of coordinated disclosure means vendors may have had little or no warning. Security Architect’s Take: Review your vulnerability management and threat intelligence feeds immediately to identify whether any of the disclosed zero-days affect your cloud workloads or underlying infrastructure. Prioritise detective controls — such as enhanced logging, anomaly detection, and WAF rule updates — for internet-facing systems until vendor patches are released. ...

29 June 2026 Â· ZX Cloud Security

CVE-2026-55200: Critical libssh2 PoC Released

🔴 Critical | Source: The Hacker News A public proof-of-concept exploit has been released for CVE-2026-55200, a critical vulnerability in libssh2, a widely used open-source library that allows applications to connect to SSH servers. A malicious or compromised SSH server can use this flaw to corrupt memory on any client using the library, potentially executing arbitrary code — without requiring any credentials or user interaction. All versions of libssh2 up to and including 1.11.1 are affected, making the blast radius extremely broad given the library’s prevalence across cloud tooling, CI/CD pipelines, and infrastructure automation. ...

29 June 2026 Â· ZX Cloud Security

CVE-2026-48558: SimpleHelp OIDC Auth Bypass

🔴 Critical | Source: CISA Known Exploited Vulnerabilities A critical authentication bypass vulnerability in SimpleHelp’s OIDC login flow allows attackers to forge identity tokens and gain full technician-level access without valid credentials. Because cryptographic signatures on identity tokens are never verified, any unauthenticated remote attacker can craft a token with arbitrary claims. In some deployments this also bypasses multi-factor authentication entirely, significantly widening the blast radius. Security Architect’s Take: Patch SimpleHelp immediately and prioritise instances exposed to the internet or integrated with your identity provider via OIDC. As an interim control, restrict access to the SimpleHelp management interface to trusted IP ranges via firewall or VPN, and audit recent technician session logs for anomalous or unexpected logins. ...

29 June 2026 Â· ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options