CVE-2026-46331: Linux pedit COW Root Exploit

🔴 Critical | Source: The Hacker News A vulnerability in the Linux kernel’s traffic-control subsystem (CVE-2026-46331, ‘pedit COW’) allows a local unprivileged user to gain root-level access by corrupting shared memory used to cache executables. A working public exploit appeared within 24 hours of the CVE being assigned on 16 June, making rapid patching critical. Any Linux-based system where untrusted users can run code — including cloud VMs and container hosts — is at risk of full local privilege escalation. ...

26 June 2026 · ZX Cloud Security

PTC Windchill RCE Flaw Added to CISA KEV Catalog

🔴 Critical | Source: The Hacker News CISA has added a critical remote code execution vulnerability in PTC Windchill PDMLink and FlexPLM — software used to manage product data and lifecycles in industrial and manufacturing environments — to its Known Exploited Vulnerabilities catalogue. Attackers are actively exploiting the flaw to deploy web shells, giving them persistent, unauthorised access to affected systems. This is particularly concerning given the prevalence of Windchill in critical manufacturing and defence supply chains. ...

26 June 2026 · ZX Cloud Security

Nation-State Actors Target Australian Critical Infrastructur

🔴 Critical | Source: The Register — Security Nation-state threat actors have successfully compromised critical Australian infrastructure, embedding access designed to enable disruptive attacks at a time of their choosing. The Australian intelligence community identified at least one separate operation in progress and coordinated with foreign counterparts to neutralise it before it could cause harm. This represents a significant escalation in state-sponsored pre-positioning within essential services. Security Architect’s Take: Audit your OT/IT network segmentation and verify that critical infrastructure control systems cannot be reached from cloud-connected environments; implement assume-breach monitoring with behavioural baselines so dormant persistent access is detectable before adversaries activate it. ...

25 June 2026 · ZX Cloud Security

CVE-2026-12569: PTC Windchill RCE Flaw Exploited

🔴 Critical | Source: CISA Known Exploited Vulnerabilities A critical remote code execution vulnerability (CVE-2026-12569) has been identified in PTC Windchill and FlexPLM, widely used product lifecycle management (PLM) platforms. An unauthenticated attacker can exploit this flaw over the network by sending a specially crafted request, requiring no prior access or credentials. This vulnerability is actively being exploited in the wild, as confirmed by CISA’s inclusion in its Known Exploited Vulnerabilities catalogue. ...

25 June 2026 · ZX Cloud Security

CVE-2026-20230: Cisco Unified CM SSRF Flaw

🔴 Critical | Source: CISA Known Exploited Vulnerabilities A server-side request forgery (SSRF) vulnerability in Cisco Unified Communications Manager (Unified CM and Unified CM SME) allows an unauthenticated remote attacker to write arbitrary files to the underlying operating system. These planted files could subsequently be leveraged to escalate privileges to root, giving an attacker full control of the system. CISA has added this to its Known Exploited Vulnerabilities catalogue, indicating active exploitation in the wild. ...

25 June 2026 · ZX Cloud Security

Cisco CVE-2026-20230 Exploited & SD-WAN 0-Day Worsens

🔴 Critical | Source: The Register — Security Cisco is facing a double blow: CVE-2026-20230 is being actively exploited in the wild, whilst a previously disclosed SD-WAN zero-day vulnerability has been reassessed as significantly more severe than initially reported. Both issues affect widely deployed Cisco infrastructure, raising the risk level for organisations relying on Cisco networking products. Security Architect’s Take: Prioritise patching CVE-2026-20230 immediately given confirmed active exploitation, and reassess your risk posture for any Cisco SD-WAN deployments in light of the upgraded severity — check Cisco’s advisories for revised CVSS scores and apply available mitigations or patches before exposure windows widen. ...

24 June 2026 · ZX Cloud Security

CVE-2025-67038: Lantronix EDS5000 Flaw Exploited

🔴 Critical | Source: The Hacker News CISA has added CVE-2025-67038, a critical code injection vulnerability (CVSS 9.8) in Lantronix EDS5000 Series device servers, to its Known Exploited Vulnerabilities catalogue following confirmed active exploitation. The flaw allows attackers to execute arbitrary code on affected devices, which are commonly used to connect serial devices to networks in industrial and enterprise environments. US federal agencies have been ordered to patch by 26 June 2026, but the active exploitation status makes this urgent for all organisations. ...

24 June 2026 · ZX Cloud Security

Cordyceps CI/CD Flaw Hits 300+ GitHub Repos

🔴 Critical | Source: The Hacker News A newly identified class of CI/CD vulnerability, dubbed ‘Cordyceps’ by Novee Security, allows attackers to hijack GitHub Actions workflows and gain full control of repositories belonging to major organisations including Microsoft, Google, and Apache. Over 300 repositories have been identified as exposed, making this a significant supply-chain risk. Because CI/CD pipelines often hold privileged credentials and publish trusted software artefacts, a successful exploit could enable attackers to inject malicious code into widely used open-source packages. ...

24 June 2026 · ZX Cloud Security

Cisco Unified CM CVE-2026-20230 Exploited in Wild

🔴 Critical | Source: The Hacker News A critical vulnerability in Cisco Unified Communications Manager (CVE-2026-20230, CVSS 8.6) allows unauthenticated remote attackers to write arbitrary files, potentially leading to root-level compromise. A public proof-of-concept exploit has accelerated active exploitation by threat actors. This affects both Unified CM and Unified CM SME, which are widely deployed enterprise telephony and call management platforms. Security Architect’s Take: Apply Cisco’s patch immediately and restrict HTTP access to Unified CM management interfaces via firewall rules or network segmentation — do not expose these systems to the internet. Audit logs for unexpected file creation or HTTP requests matching the exploit pattern as indicators of compromise. ...

24 June 2026 · ZX Cloud Security

FortiBleed: 110M Credentials Stolen from FortiGate Firewalls

🔴 Critical | Source: The Hacker News A financially motivated Russian-speaking threat actor has been running a large-scale attack campaign dubbed FortiBleed since February 2026, targeting over 430,000 FortiGate firewalls worldwide and harvesting more than 110 million credentials. The operation combines scanning for exposed services, brute-force attacks, and custom tooling to gain initial access at scale. The sheer volume of compromised credentials and affected devices makes this a significant supply-chain risk for any organisation relying on Fortinet perimeter security. ...

23 June 2026 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options