CVE-2026-55040: Unauthenticated RCE in SharePoint

🔴 Critical | Source: The Hacker News A critical vulnerability in Microsoft SharePoint Server (CVE-2026-55040, CVSS 9.1) allows attackers to impersonate any user, including administrators, without needing valid credentials, ultimately enabling unauthenticated remote code execution. The exploit chain was discovered with significant assistance from an AI agent, marking a notable development in AI-assisted vulnerability research. Affected versions include SharePoint Server Subscription Edition, 2019, and 2016. Security Architect’s Take: Prioritise emergency patching of all on-premises SharePoint Server instances (Subscription Edition, 2019, 2016) immediately; if patching cannot be completed within 24–48 hours, consider isolating SharePoint servers from internet exposure and enforcing network-level access controls to reduce attack surface whilst remediation is under way. ...

11 August 2026 Â· ZX Cloud Security

CVE-2026-65768: Microsoft Teams Android RCE Flaw

🔴 Critical | Source: Microsoft Security Response Center A path traversal vulnerability in Microsoft Teams for Android allows an unauthenticated attacker to remotely execute arbitrary code on affected devices without requiring user interaction beyond having the app installed. The flaw arises from insufficient restrictions on file path handling, potentially giving attackers a foothold on corporate mobile devices. Given the widespread enterprise use of Teams on Android, the exposure across large organisations could be significant. ...

11 August 2026 Â· ZX Cloud Security

CVE-2021-34474: Dynamics 365 Business Central RCE

🔴 Critical | Source: Microsoft Security Response Center CVE-2021-34474 is a remote code execution vulnerability in Microsoft Dynamics 365 Business Central, a cloud-based ERP platform. This update revises the affected build numbers but introduces no new patches or mitigations. Organisations running unpatched versions of Business Central remain at risk of an attacker executing arbitrary code on affected systems. Security Architect’s Take: Verify that your Dynamics 365 Business Central deployments are running the corrected build numbers listed in the updated advisory, and ensure the original July 2021 patches have been applied. If Business Central is internet-facing or integrated with other Azure services, prioritise confirmation of patch status given the remote code execution impact. ...

10 August 2026 Â· ZX Cloud Security

CVE-2026-47243: Kata Container Escape via virtiofs on Azure

🔴 Critical | Source: Microsoft Security Response Center CVE-2026-47243 is a critical vulnerability in the Kata Containers runtime-rs implementation that allows an attacker with root access inside a Kata guest VM to escape the container sandbox and gain root-level access on the underlying host via the virtiofs filesystem sharing mechanism. This is a full container escape, bypassing the hardware virtualisation boundary that Kata Containers is specifically designed to enforce. It is particularly significant for Azure customers using confidential or sandboxed container workloads where strong isolation guarantees are assumed. ...

9 August 2026 Â· ZX Cloud Security

CVE-2026-64676: Kata Containers Confidential VM Memory Tampe

🔴 Critical | Source: Microsoft Security Response Center CVE-2026-64676 is a vulnerability in Kata Containers where unauthorised access to mem-agent ttRPC methods allows an untrusted host to tamper with the memory of a confidential guest workload. This undermines the core security guarantee of confidential computing — that a cloud host or hypervisor cannot read or alter a tenant’s protected workload. The impact is particularly severe for organisations using Azure confidential VMs or AKS with confidential node pools that rely on Kata Containers for hardware-enforced isolation. ...

9 August 2026 Â· ZX Cloud Security

Metabase Zero-Day: Unauth Admin Access Exploited

🔴 Critical | Source: The Hacker News A critical zero-day vulnerability in Metabase, a widely used business intelligence and data visualisation tool, is being actively exploited in the wild. The flaw carries a maximum CVSS score of 10.0 and allows unauthenticated attackers to inject arbitrary SQL into the Metabase database, potentially granting full administrative access. Because no CVE identifier has been assigned yet and exploitation is already occurring, organisations running Metabase face immediate risk. ...

8 August 2026 Â· ZX Cloud Security

N-able N-central Hotfix 2: Active RMM Exploitation Alert

🔴 Critical | Source: The Hacker News N-able has issued a second hotfix for its N-central Remote Monitoring and Management (RMM) platform following active exploitation of a recently disclosed vulnerability. Attackers are moving beyond initial access to reach managed endpoints and establish persistence, meaning the blast radius extends to every device managed through affected N-central instances. This is a live, evolving incident requiring urgent action from Managed Service Providers (MSPs) and their customers. ...

8 August 2026 Â· ZX Cloud Security

CVE-2026-8037: Kemp LoadMaster Flaw Added to CISA KEV

🔴 Critical | Source: The Hacker News A critical command injection vulnerability (CVE-2026-8037, CVSS 9.6) in Progress Kemp LoadMaster has been added to CISA’s Known Exploited Vulnerabilities catalogue following nearly 800 confirmed exploitation attempts in the wild. LoadMaster is a widely deployed application delivery controller and load balancer used across enterprise and cloud environments. The flaw allows attackers to execute arbitrary commands, potentially leading to full system compromise. Security Architect’s Take: Patch Progress Kemp LoadMaster immediately if deployed in your environment, and audit internet-facing instances for signs of compromise — prioritise any LoadMaster nodes sitting at the perimeter or in front of critical workloads. If patching cannot be applied immediately, restrict management interface access to trusted IP ranges and review firewall rules to limit exposure. ...

8 August 2026 Â· ZX Cloud Security

N-able N-central God Mode Flaw: Customer Networks Breached

🔴 Critical | Source: The Register — Security N-able has confirmed that attackers exploited a critical privilege escalation flaw in its N-central remote monitoring and management platform, using administrative access to pivot downstream into customer networks. A second hotfix has been issued after the first proved insufficient. The incident highlights the severe supply chain risk posed by RMM tools, which by design hold broad access to managed environments. Security Architect’s Take: If your organisation uses N-central, apply the latest hotfix immediately and audit downstream access logs for lateral movement or unusual admin activity originating from N-able infrastructure. Consider temporarily restricting N-central’s network reach to only essential endpoints until you can confirm your environment was not traversed. ...

7 August 2026 Â· ZX Cloud Security

WordPress CVE-2026-64638: Pre-Auth XSS to PHP RCE

🔴 Critical | Source: The Hacker News A pre-authentication reflected XSS vulnerability (CVE-2026-64638, CVSS 8.9) has been discovered in the WordPress login screen, affecting all versions of the CMS. Researchers at pwn.ai demonstrated that the flaw can be chained to achieve remote PHP code execution on the server, requiring only that a logged-in administrator visits an attacker-controlled page. WordPress has released a patch and organisations should treat this as an urgent update given the low barrier to initial exploitation. ...

7 August 2026 Â· ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options