CVE-2026-45480: Azure Active Directory Privilege Escalation

🔴 Critical | Source: Microsoft Security Response Center A vulnerability in Azure Active Directory (CVE-2026-45480) allows an unauthenticated attacker to elevate their privileges over a network by exploiting improper authentication handling. This means an attacker without valid credentials could potentially gain elevated access to resources protected by Azure AD. Given how central Azure AD is to identity and access management across Microsoft cloud environments, the potential impact is significant. Security Architect’s Take: Review Azure AD audit logs immediately for anomalous authentication events and ensure Conditional Access policies with strong MFA enforcement are in place; apply any Microsoft-issued patches or mitigations as a priority, and consider temporarily tightening network-level access to Azure AD endpoints where feasible. ...

18 June 2026 Â· ZX Cloud Security

CVE-2026-20253: Splunk Enterprise Auth Bypass Flaw

🔴 Critical | Source: CISA Known Exploited Vulnerabilities A critical vulnerability in Splunk Enterprise allows unauthenticated attackers to create or delete arbitrary files via an exposed PostgreSQL sidecar service endpoint that lacks proper authentication controls. This could enable attackers to corrupt data, disrupt logging pipelines, or potentially escalate to full system compromise. It is listed on the CISA Known Exploited Vulnerabilities catalogue, confirming active exploitation in the wild. Security Architect’s Take: Immediately apply Splunk’s patch ahead of the 21 June 2026 remediation deadline, and in the interim restrict network access to the PostgreSQL sidecar service endpoint using firewall rules or security group policies so it is not reachable from untrusted networks. ...

18 June 2026 Â· ZX Cloud Security

Fortinet Firewall Attack Steals Passwords on 75k Devices

🔴 Critical | Source: The Register — Security A large-scale credential-theft campaign has compromised approximately 75,000 Fortinet firewall devices, exfiltrating stored passwords. The attack exploits exposed management interfaces or known vulnerabilities to harvest credentials at scale. This poses a significant risk to organisations using FortiGate appliances, particularly those with internet-facing management planes. Security Architect’s Take: Immediately rotate all credentials associated with affected Fortinet devices, including VPN accounts, local admin accounts, and any downstream systems that share those credentials. Audit your FortiGate estate for internet-exposed management interfaces and restrict access to trusted IP ranges via firewall policy or a jump host. ...

17 June 2026 Â· ZX Cloud Security

Cisco SD-WAN Max-Severity Bug Expands: Check Your Logs

🔴 Critical | Source: The Register — Security Cisco has expanded a maximum-severity security advisory to include an additional SD-WAN device affected by a critical vulnerability. The flaw carries the highest possible CVSS score, meaning it could allow an attacker to fully compromise affected devices without authentication. Organisations that applied patches at the time of the original advisory may still need to review logs for signs of prior exploitation. Security Architect’s Take: If you operate Cisco SD-WAN infrastructure, verify the updated advisory to confirm whether the newly added device is in your estate, and conduct a thorough review of device logs and NetFlow data for indicators of compromise — even if you patched promptly after the original disclosure. ...

17 June 2026 Â· ZX Cloud Security

CVE-2026-48907: Joomla JCE RCE Flaw Actively Exploited

🔴 Critical | Source: The Hacker News A critical vulnerability (CVE-2026-48907, CVSS 10.0) in the Joomla Content Editor (JCE) plugin allows attackers to bypass access controls and execute arbitrary PHP code on affected servers. CISA has added it to its Known Exploited Vulnerabilities catalogue, confirming active exploitation in the wild. Any internet-facing Joomla site running the JCE plugin is at serious risk of full server compromise. Security Architect’s Take: Immediately audit your estate and cloud-hosted workloads for any Joomla installations running the JCE plugin and apply the vendor patch as an emergency change. If patching cannot be done promptly, take affected instances offline or block public access to the Joomla admin and editor endpoints via WAF or security group rules. ...

17 June 2026 Â· ZX Cloud Security

Critical Fortinet FortiSandbox Bugs Actively Exploited

🔴 Critical | Source: The Register — Security Three critical vulnerabilities in Fortinet’s FortiSandbox product have been actively exploited by unknown attackers in the wild. Patches are available for all three flaws, making urgent remediation essential for any organisation running FortiSandbox. The active exploitation status significantly raises the risk, as attackers are already leveraging these weaknesses before many organisations have had a chance to respond. Security Architect’s Take: If FortiSandbox is deployed anywhere in your environment — on-premises or integrated with cloud workloads — prioritise patching immediately and review logs for indicators of compromise prior to the patch window. Isolate affected appliances from the network if an immediate upgrade is not possible. ...

16 June 2026 Â· ZX Cloud Security

Fortinet FortiSandbox CVE-2026-39813 Exploited in Wild

🔴 Critical | Source: The Hacker News Attackers are actively exploiting three vulnerabilities in Fortinet FortiSandbox, a network security sandboxing product, including a critical path traversal flaw (CVE-2026-39813, CVSS 9.1) in its JRPC API. Two additional CVEs — CVE-2026-39808 and CVE-2026-25089 — are also being abused in the wild, with at least one patched only last week. Active exploitation makes this an urgent patching priority for any organisation running FortiSandbox. Security Architect’s Take: Immediately apply the latest Fortinet patches for FortiSandbox and audit internet-facing exposure of the JRPC API — if it does not need to be externally accessible, restrict it at the network perimeter. Check threat intelligence feeds and FortiSandbox logs for indicators of compromise consistent with path traversal attempts. ...

16 June 2026 Â· ZX Cloud Security

CVE-2026-48907: Joomla Plugin RCE via File Upload

🔴 Critical | Source: CISA Known Exploited Vulnerabilities A critical vulnerability in the Widget Factory Joomla Content Editor plugin allows unauthenticated attackers to upload and execute arbitrary PHP code by creating new editor profiles. This effectively grants full remote code execution on affected Joomla sites without requiring any login credentials. It has been added to the CISA Known Exploited Vulnerabilities catalogue, confirming active exploitation in the wild. Security Architect’s Take: Audit all Joomla deployments across your environment and patch or disable the Widget Factory Content Editor plugin immediately. If Joomla sites are hosted on cloud infrastructure, treat any exposed instance as potentially compromised and review web application firewall rules to block unauthenticated POST requests to editor profile creation endpoints whilst patching is carried out. ...

16 June 2026 Â· ZX Cloud Security

Cisco SD-WAN Manager Root Bug Actively Exploited

🔴 Critical | Source: The Register — Security A privilege escalation vulnerability in Cisco Catalyst SD-WAN Manager is being actively exploited as a zero-day, allowing attackers to gain root-level access on affected systems. This is the second Cisco Catalyst SD-WAN Manager flaw exploited in the wild this month, suggesting targeted or opportunistic campaigns against network infrastructure. SD-WAN management planes are high-value targets as compromise can provide broad visibility and control over enterprise network traffic. ...

15 June 2026 Â· ZX Cloud Security

LiteLLM Vuln Chain: Low-Privilege to Full Server Takeover

🔴 Critical | Source: The Hacker News A chain of three vulnerabilities in LiteLLM, a popular open-source AI gateway, allows a low-privilege user to escalate to full admin and execute arbitrary code on the server. Because LiteLLM proxies requests to over 100 AI model providers, a successful attack exposes every API key and secret stored on the instance. Researchers at Obsidian Security disclosed the issue, making it an urgent concern for any organisation running LiteLLM in production. ...

15 June 2026 Â· ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options