CVE-2023-4346: KNX Protocol Device Lockout Flaw

🔴 Critical | Source: CISA Known Exploited Vulnerabilities CVE-2023-4346 affects the KNX building automation protocol, where a flaw in Connection Authorization Option 1 allows an attacker to wipe all devices on a KNX installation and set a BCU key to permanently lock them out — without needing any additional security credentials. This is a known-exploited vulnerability, meaning it has been actively used in real-world attacks. Buildings using KNX-based smart systems for lighting, HVAC, and access control may be at risk of operational disruption or physical security compromise. ...

15 July 2026 Â· ZX Cloud Security

CVE-2026-46817: Oracle E-Business Suite Payments Flaw

🔴 Critical | Source: CISA Known Exploited Vulnerabilities A critical vulnerability in Oracle E-Business Suite allows an unauthenticated attacker with network access over HTTP to fully compromise Oracle Payments, potentially taking complete control of the payment processing component. The flaw stems from improper privilege management, meaning no credentials are required to exploit it. This vulnerability is confirmed as actively exploited in the wild, making prompt remediation urgent. Security Architect’s Take: Immediately restrict network access to Oracle E-Business Suite HTTP endpoints at the perimeter and WAF level, prioritising isolation of the Oracle Payments module. Apply Oracle’s patch before the CISA remediation deadline of 18 July 2026, and audit access logs for any anomalous unauthenticated HTTP activity against the Payments component. ...

15 July 2026 Â· ZX Cloud Security

Microsoft Patch Tuesday: 622 CVEs Fixed July 2026

🔴 Critical | Source: The Register — Security Microsoft’s July 2026 Patch Tuesday has released fixes for a staggering 622 CVEs, more than tripling the previous month’s record-breaking 206. The sheer volume signals either a significant backlog being cleared or a dramatic increase in vulnerability discovery across Microsoft’s product estate. For security teams, this represents an enormous patching burden that demands careful prioritisation. Security Architect’s Take: Immediately triage the 622 CVEs by severity and exploitability, focusing first on any Remote Code Execution or Privilege Escalation vulnerabilities affecting Azure, Windows Server, and identity services. Use Microsoft’s Exploitability Index and cross-reference with CISA’s KEV catalogue to drive your patching order, and consider accelerating deployment pipelines for critical cloud-hosted workloads. ...

14 July 2026 Â· ZX Cloud Security

Microsoft Patches 622 Flaws & Two Zero-Days July 2025

🔴 Critical | Source: The Hacker News Microsoft’s July 2025 Patch Tuesday is the largest on record, addressing 622 CVEs — more than triple the previous monthly high. Two of those vulnerabilities are zero-days already being actively exploited in the wild, making immediate prioritisation essential. The sheer scale of this release significantly increases the attack surface for any organisation running Microsoft or Azure-dependent workloads. Security Architect’s Take: Prioritise the two actively exploited zero-days immediately — identify affected systems via Microsoft’s Security Update Guide and expedite patching through your change management process outside the normal cycle if necessary. Given the record volume of fixes, triage the remaining CVEs by CVSS score and exposure, focusing on internet-facing and identity-related components first. ...

14 July 2026 Â· ZX Cloud Security

CVE-2026-44747: SAP NetWeaver ABAP CVSS 9.9 Flaw Patched

🔴 Critical | Source: The Hacker News SAP has issued a critical patch for CVE-2026-44747, a CVSS 9.9 out-of-bounds write vulnerability in SAP NetWeaver Application Server ABAP. The flaw allows an authenticated attacker to corrupt memory through logical errors in memory management, potentially exposing or modifying sensitive data. Given NetWeaver ABAP’s widespread use as a core enterprise application platform, the blast radius for unpatched systems is substantial. Security Architect’s Take: Prioritise patching SAP NetWeaver ABAP instances immediately as part of an emergency change — a CVSS 9.9 with authenticated access as the only barrier is highly exploitable in environments with broad internal user bases or compromised accounts. Review SAP Security Note for CVE-2026-44747, confirm patch deployment across all landscapes (development, QA, production), and validate that SAP systems are not directly internet-exposed without a WAF or SAP Web Dispatcher. ...

14 July 2026 Â· ZX Cloud Security

CVE-2026-42990: SQL Server ODBC Driver RCE Flaw

🔴 Critical | Source: Microsoft Security Response Center A heap-based buffer overflow vulnerability in Microsoft’s SQL Server ODBC driver allows an unauthenticated attacker to remotely execute arbitrary code over a network without requiring any user interaction. The flaw is classified as an Elevation of Privilege vulnerability, meaning successful exploitation could grant an attacker significantly elevated permissions on affected systems. Any environment using the SQL Server ODBC driver — including Azure-hosted SQL workloads — should treat this as an urgent patching priority. ...

14 July 2026 Â· ZX Cloud Security

CVE-2026-48561: Microsoft Copilot RCE Vulnerability

🔴 Critical | Source: Microsoft Security Response Center A command injection vulnerability in Microsoft Copilot allows an unauthenticated attacker to execute arbitrary code remotely over a network, without requiring any user interaction or elevated privileges. This is a serious flaw because Copilot is deeply integrated into Microsoft 365 and Azure services, meaning exploitation could give an attacker a foothold across a broad range of enterprise environments. Organisations using Microsoft Copilot should treat this as a priority remediation. ...

14 July 2026 Â· ZX Cloud Security

CVE-2026-49164: AD Domain Services RCE Flaw

🔴 Critical | Source: Microsoft Security Response Center A heap-based buffer overflow vulnerability in Windows Active Directory Domain Services allows an unauthenticated attacker to remotely execute arbitrary code over a network without any user interaction. Active Directory is the backbone of identity and access management in most enterprise Windows environments, meaning a successful exploit could grant an attacker deep control over an organisation’s entire directory infrastructure. This makes it an exceptionally high-impact vulnerability, particularly for hybrid cloud environments where on-premises AD is federated with Azure Active Directory (Entra ID). ...

14 July 2026 Â· ZX Cloud Security

Joomla Extensions CVSSv3 10.0 Flaws Exploited in Wild

🔴 Critical | Source: The Register — Security Attackers are actively exploiting critical vulnerabilities (CVSS 10.0) in two popular Joomla extensions — iCagenda and Balbooa Forms — to compromise websites running the open-source CMS. Joomla powers approximately one million sites worldwide, making the blast radius of these flaws considerable. The perfect severity scores indicate these bugs are trivially exploitable and require no authentication or special privileges. Security Architect’s Take: If your organisation hosts or manages any Joomla-based sites, audit installed extensions immediately and apply patches for iCagenda and Balbooa Forms without delay. Where immediate patching isn’t possible, use a web application firewall (WAF) to block exploit attempts and consider temporarily disabling the affected extensions until remediation is confirmed. ...

14 July 2026 Â· ZX Cloud Security

Russia Blamed for Poland Power Grid Cyberattack

🔴 Critical | Source: The Register — Security The EU and UK have formally attributed a cyberattack on Poland’s power grid to Russian state-sponsored actors, specifically the GRU-linked group Sandworm. The attack, which targeted critical energy infrastructure, had the potential to cut power to approximately half a million people during winter. Sweeping sanctions have been announced against individuals and entities linked to the operation. Security Architect’s Take: Organisations operating or supporting critical national infrastructure should treat this as a prompt to review their OT/IT network segmentation, ensure industrial control systems are air-gapped or strictly access-controlled, and validate that incident response playbooks explicitly cover state-sponsored threat scenarios including destructive malware targeting energy systems. ...

13 July 2026 Â· ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options