CVE-2025-67038: Lantronix EDS5000 RCE Flaw

šŸ”“ Critical |Ā Source: CISA Known Exploited Vulnerabilities A critical code injection vulnerability in the Lantronix EDS5000 device server allows attackers to inject arbitrary operating system commands via the username parameter. These commands execute with root privileges, giving an attacker full control over the affected device. The flaw is listed in CISA’s Known Exploited Vulnerabilities catalogue, confirming active exploitation in the wild. Security Architect’s Take: Audit your network for any Lantronix EDS5000 devices, particularly those exposed at the network edge or used to bridge serial devices to cloud-connected infrastructure. Apply vendor patches immediately, restrict management interface access to trusted networks only, and treat any device potentially exposed to untrusted input as compromised pending remediation. ...

23 June 2026 Ā· ZX Cloud Security

CVE-2026-34908: Ubiquiti UniFi OS Access Control Flaw

šŸ”“ Critical |Ā Source: CISA Known Exploited Vulnerabilities A vulnerability in Ubiquiti’s UniFi OS allows anyone with network access to make unauthorised changes to affected devices without proper authentication or authorisation checks. This is actively being exploited in the wild, as confirmed by CISA’s inclusion in their Known Exploited Vulnerabilities catalogue. UniFi OS underpins a wide range of Ubiquiti networking hardware commonly deployed in enterprise and hybrid cloud environments, making the blast radius potentially significant. ...

23 June 2026 Ā· ZX Cloud Security

CVE-2026-34909: Ubiquiti UniFi OS Path Traversal Flaw

šŸ”“ Critical |Ā Source: CISA Known Exploited Vulnerabilities A path traversal vulnerability in Ubiquiti UniFi OS allows an attacker with network access to read files on the underlying system, potentially enabling them to compromise accounts. The flaw is listed on CISA’s Known Exploited Vulnerabilities catalogue, meaning it is actively being exploited in the wild. Organisations running UniFi network infrastructure should treat this as an urgent remediation priority. Security Architect’s Take: Audit your environment for any internet- or management-network-exposed UniFi OS devices and apply vendor patches immediately, with a hard deadline of 26 June 2026 per CISA guidance. As an interim control, restrict access to UniFi management interfaces to trusted, segmented management networks and enforce MFA on any administrative accounts. ...

23 June 2026 Ā· ZX Cloud Security

CVE-2026-34910: Ubiquiti UniFi OS Command Injection

šŸ”“ Critical |Ā Source: CISA Known Exploited Vulnerabilities A command injection vulnerability in Ubiquiti UniFi OS allows an attacker with network access to execute arbitrary commands on affected devices. The flaw stems from improper input validation and has been confirmed as actively exploited, prompting CISA to add it to its Known Exploited Vulnerabilities catalogue. UniFi OS underpins a wide range of Ubiquiti networking hardware commonly deployed in enterprise and hybrid environments. ...

23 June 2026 Ā· ZX Cloud Security

BootROM Exploit Drops for A12 & A13 iPhones — Unpatchable

šŸ”“ Critical |Ā Source: The Register — Security Security researchers have published a checkm8-style unpatchable BootROM exploit targeting Apple iPhones running A12 and A13 chips, including the iPhone XS through iPhone 11 series. Because the vulnerability exists in read-only boot firmware, Apple cannot issue a software patch — the only fix is a hardware replacement. This gives attackers a persistent, low-level foothold on affected devices that survives factory resets and OS reinstalls. ...

19 June 2026 Ā· ZX Cloud Security

AutoJack: AI Agent RCE via Malicious Web Page

šŸ”“ Critical |Ā Source: The Hacker News Microsoft researchers have disclosed ā€˜AutoJack’, an exploit chain that weaponises AI browsing agents to achieve remote code execution on the host machine. An attacker simply needs to lure the agent to a malicious web page; JavaScript on that page communicates with a privileged local service to spawn a process — requiring no credentials or user interaction beyond the initial navigation. This is significant because it demonstrates that AI agents, which often run with elevated local privileges, dramatically expand the attack surface of any machine they operate on. ...

19 June 2026 Ā· ZX Cloud Security

FortiBleed: 86,644 FortiGate Devices Compromised

šŸ”“ Critical |Ā Source: The Hacker News A large-scale campaign dubbed ā€˜FortiBleed’, attributed to Russian-speaking threat actors, has compromised over 86,000 internet-facing Fortinet FortiGate devices. CISA has issued an urgent advisory urging organisations to take immediate protective action. The scale of the compromise and state-linked attribution make this a significant threat to enterprise and government networks globally. Security Architect’s Take: Immediately audit all internet-exposed FortiGate appliances, apply the latest firmware patches, and review management interface access — restricting it to trusted IP ranges or a private network. Check device logs and SSL-VPN session records for indicators of compromise, and consider isolating affected devices pending forensic review. ...

19 June 2026 Ā· ZX Cloud Security

CVE-2026-48914: QEMU-KVM Heap Overflow in Azure

šŸ”“ Critical |Ā Source: Microsoft Security Response Center CVE-2026-48914 is a heap buffer overflow vulnerability in QEMU-KVM’s virtio-blk driver, specifically in how it handles SCSI requests. This type of flaw can potentially allow a malicious guest virtual machine to corrupt host memory, which in a cloud environment could lead to VM escape — one of the most severe hypervisor-level threats. Microsoft has published this advisory via the MSRC, indicating Azure infrastructure may be affected. ...

19 June 2026 Ā· ZX Cloud Security

AWS containerd CRI Flaws: CVE-2026-50195 & More

šŸ”“ Critical |Ā Source: AWS Security Bulletins AWS has identified five vulnerabilities in containerd’s Container Runtime Interface (CRI) plugin affecting versions 1.7 through 2.3, impacting managed services including EKS, ECS, Fargate, Bottlerocket, and Amazon Linux. The flaws range from arbitrary host file reads and command execution via image labels, to container checkpoint abuse and a runtime denial-of-service. Exploitation could allow a malicious container image or checkpoint to compromise host systems or disrupt container workloads. ...

19 June 2026 Ā· ZX Cloud Security

Critical NGINX RCE Flaws Patched – CVE-2026-42530

šŸ”“ Critical |Ā Source: The Hacker News F5 has patched two critical vulnerabilities in NGINX Open Source, both of which could allow a remote, unauthenticated attacker to execute arbitrary code on affected systems. The flaws reside in the HTTP/3 module and carry a CVSS v4 score of 9.2, indicating high exploitability with no authentication required. NGINX is one of the world’s most widely deployed web servers and reverse proxies, making the blast radius of these vulnerabilities significant. ...

18 June 2026 Ā· ZX Cloud Security

šŸ“¬ Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options