wp2shell WordPress RCE Flaw: Patch to 6.9.5 or 7.0.2 Now

🔴 Critical | Source: The Hacker News A critical unauthenticated remote code execution vulnerability, dubbed wp2shell, exists in WordPress core versions 6.9 and 7.0, meaning any site running a default installation — with no plugins — could be fully compromised via a single anonymous HTTP request. WordPress has patched the flaw in versions 6.9.5 and 7.0.2 and has pushed forced auto-updates to affected sites. The vulnerability was discovered by Adam Kues at Assetnote, the attack surface management arm of Searchlight Cyber. ...

17 July 2026 Â· ZX Cloud Security

FortiSandbox Command Injection Flaws Actively Exploited

🔴 Critical | Source: The Register — Security Critical command injection vulnerabilities in Fortinet’s FortiSandbox product are being actively exploited by attackers, prompting CISA to issue a mandatory patch order. FortiSandbox is used by organisations to analyse potentially malicious files and URLs in an isolated environment. Active exploitation means unpatched systems are at immediate risk of compromise, potentially allowing attackers to execute arbitrary commands on the underlying host. Security Architect’s Take: Prioritise patching FortiSandbox instances immediately, particularly any internet-exposed or perimeter-adjacent deployments — CISA’s order applies to US federal agencies but the active exploitation makes this urgent for all organisations. Review firewall rules to restrict management interface access to trusted IPs only while patches are applied. ...

17 July 2026 Â· ZX Cloud Security

CVE-2026-58644: SharePoint RCE Zero-Day Added to CISA KEV

🔴 Critical | Source: The Hacker News A critical zero-day vulnerability (CVE-2026-58644, CVSS 9.8) in Microsoft SharePoint Server allows remote code execution via a deserialization flaw and is already being actively exploited in the wild. CISA has added it to its Known Exploited Vulnerabilities catalogue, mandating that US federal agencies patch by 19 July 2026. Given SharePoint’s widespread use as a collaboration platform, the blast radius for unpatched organisations is significant. ...

17 July 2026 Â· ZX Cloud Security

CVE-2026-59117 Windows Terminal RCE Vulnerability

🔴 Critical | Source: Microsoft Security Response Center CVE-2026-59117 is a remote code execution vulnerability in Windows Terminal caused by an integer overflow flaw, meaning an attacker on a network could potentially run malicious code on an affected system without needing valid credentials. This is particularly concerning in cloud and enterprise environments where Windows Terminal is commonly used by engineers and administrators to manage Azure resources. If exploited, an attacker could gain a foothold on a privileged workstation, potentially escalating access to connected cloud infrastructure. ...

16 July 2026 Â· ZX Cloud Security

CVE-2026-53412: Critical Zoom Windows Flaw Patched

🔴 Critical | Source: The Hacker News Zoom has patched a critical vulnerability (CVE-2026-53412, CVSS 9.8) in its Windows Desktop Client, VDI Client, and Meeting SDK caused by improper input validation. The flaw could allow an attacker to take over a victim’s Zoom account without requiring authentication. Given the near-maximum CVSS score and the widespread enterprise use of Zoom, the potential blast radius is significant. Security Architect’s Take: Prioritise patching Zoom Desktop Client, VDI Client, and Meeting SDK for Windows across your estate immediately — a CVSS 9.8 with account takeover potential warrants emergency change procedures. Ensure your software inventory and endpoint management tooling (e.g. Intune, SCCM) can confirm patched version deployment, and consider restricting Zoom VDI Client access until remediation is confirmed in high-sensitivity environments. ...

16 July 2026 Â· ZX Cloud Security

CVE-2026-25089: Fortinet FortiSandbox RCE Flaw

🔴 Critical | Source: CISA Known Exploited Vulnerabilities A critical OS command injection vulnerability in Fortinet FortiSandbox (including its cloud and PaaS variants) allows an unauthenticated attacker to run arbitrary commands simply by sending crafted HTTP requests — no login required. This is actively being exploited in the wild, as confirmed by CISA’s addition to its Known Exploited Vulnerabilities catalogue. The potential impact is severe, as FortiSandbox is a security control itself, meaning compromise could blind an organisation to other threats. ...

16 July 2026 Â· ZX Cloud Security

CVE-2026-39808: Fortinet FortiSandbox RCE Flaw

🔴 Critical | Source: CISA Known Exploited Vulnerabilities A critical OS command injection vulnerability in Fortinet FortiSandbox allows an unauthenticated attacker to execute arbitrary commands on the affected system by sending specially crafted HTTP requests. This requires no prior authentication, significantly lowering the bar for exploitation. CISA has confirmed active exploitation in the wild, making immediate remediation essential. Security Architect’s Take: Audit your estate for any internet-exposed FortiSandbox instances and apply Fortinet’s patch immediately — CISA’s remediation deadline is 19 July 2026. As an interim measure, restrict management interface access to trusted IP ranges via network ACLs or firewall rules to reduce the attack surface. ...

16 July 2026 Â· ZX Cloud Security

CVE-2026-58644: Microsoft SharePoint RCE Flaw

🔴 Critical | Source: CISA Known Exploited Vulnerabilities A critical vulnerability in Microsoft SharePoint allows attackers to execute arbitrary code remotely by exploiting unsafe handling of untrusted data during deserialization. This flaw requires no authentication, meaning an attacker with network access could compromise a SharePoint server without any credentials. It is actively being exploited in the wild, making immediate patching essential. Security Architect’s Take: Prioritise applying Microsoft’s patch before the CISA remediation deadline of 19 July 2026; in the interim, restrict network access to SharePoint instances at the perimeter and review audit logs for anomalous deserialization activity or unexpected process spawning from SharePoint worker processes. ...

16 July 2026 Â· ZX Cloud Security

Firefox CVE-2026-15718 & CVE-2026-15719: Critical Patches

🔴 Critical | Source: The Hacker News Mozilla has released emergency patches for Firefox addressing two critical vulnerabilities — CVE-2026-15718 (an invalid pointer in the WebAssembly engine) and CVE-2026-15719 (a site isolation bypass in DOM navigation) — with exploit code already publicly available. Alongside Firefox, updates for Chrome, Adobe, and VMware are also included in this patch cycle, addressing multiple critical flaws across widely deployed software. The public availability of exploit code significantly raises the risk of active exploitation in the near term. ...

15 July 2026 Â· ZX Cloud Security

SonicWall SMA 1000 Zero-Days CVE-2026-15409 Exploited

🔴 Critical | Source: The Hacker News SonicWall has disclosed two actively exploited zero-day vulnerabilities in its SMA 1000 series remote access appliances. The most severe, CVE-2026-15409, carries a maximum CVSS score of 10.0 and allows unauthenticated remote attackers to execute arbitrary commands via a server-side request forgery flaw. Both vulnerabilities are already being exploited in the wild, making this an urgent patching priority for any organisation relying on SMA 1000 devices for remote access. ...

15 July 2026 Â· ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options