Joomla Zero-Days: iCagenda & Balbooa CVSS 10.0 Flaws

🔴 Critical | Source: The Hacker News Two Joomla extensions — iCagenda and Balbooa Forms — have been assigned maximum CVSS scores of 10.0 and confirmed as actively exploited zero-days, prompting CISA to add them to its Known Exploited Vulnerabilities catalogue. These flaws affect widely used Joomla plugins, meaning any organisation running affected versions faces immediate, critical risk. Zero-day status indicates attackers were exploiting these vulnerabilities before patches were available. Security Architect’s Take: Audit all Joomla deployments in your estate immediately and identify any instances running iCagenda or Balbooa Forms extensions; apply vendor patches or remove the extensions without delay. If patching is not immediately possible, consider taking affected Joomla sites offline or placing them behind a WAF with virtual patching rules targeting these CVEs. ...

13 July 2026 · ZX Cloud Security

CVE-2008-4128: Cisco IOS CSRF Exploit Alert

🔴 Critical | Source: CISA Known Exploited Vulnerabilities A vulnerability in Cisco IOS 12.4 allows remote attackers to perform cross-site request forgery (CSRF) attacks, tricking authenticated users into executing arbitrary commands on the router via specially crafted URLs. This can result in full device compromise at privilege level 15, the highest administrative tier. Despite its age, CISA has confirmed active exploitation, making remediation urgent. Security Architect’s Take: Audit your estate for any Cisco IOS 12.4 devices — particularly those with HTTP/HTTPS management interfaces exposed — and disable the web-based management interface immediately where not required. Apply available patches or upgrade IOS versions, and enforce network-level controls to restrict management plane access to trusted IP ranges only. ...

13 July 2026 · ZX Cloud Security

jscrambler 8.14.0 npm Supply Chain Attack: Infostealer

🔴 Critical | Source: The Hacker News The jscrambler npm package version 8.14.0 was compromised and contained a malicious preinstall hook that automatically downloaded and executed a Rust-based infostealer on Windows, macOS, and Linux. Any developer or CI/CD pipeline that ran ’npm install’ with this version was immediately exposed without any further interaction required. Socket detected the malicious release within six minutes of publication, but the window of exposure remains a concern for any environment that pulled the package during that period. ...

11 July 2026 · ZX Cloud Security

Critical Zimbra XSS Flaw Allows Code Execution via Email

🔴 Critical | Source: The Hacker News A critical stored cross-site scripting (XSS) vulnerability in Zimbra’s Classic Web Client allows attackers to embed malicious scripts inside specially crafted emails, which then execute within the victim’s browser session when the email is viewed. No CVE identifier has been assigned yet, but Zimbra has issued updates and is urging immediate patching. The flaw is particularly dangerous because exploitation requires nothing more than a target opening a malicious email. ...

11 July 2026 · ZX Cloud Security

Progress ShareFile Storage Zone Controller Shutdown Alert

🔴 Critical | Source: The Hacker News Progress Software has issued an urgent directive to ShareFile customers to shut down their on-premises Storage Zone Controller Windows servers in response to a credible, unspecified external security threat. The company has proactively disabled access to affected accounts whilst it investigates. The nature of the threat has not been publicly disclosed, but the severity of the response suggests a potentially serious vulnerability or active exploitation. ...

10 July 2026 · ZX Cloud Security

Ill Bloom Wallet Flaw Exploited: $5M Drained

🔴 Critical | Source: The Hacker News A vulnerability dubbed ‘Ill Bloom’, disclosed by security firm Coinspect, allows attackers to predict cryptocurrency wallet recovery phrases due to weak randomness in how some wallet software generates them. With knowledge of the recovery phrase, an attacker gains full control of the associated wallet and can drain all funds. Exploits are already active, with a confirmed coordinated attack on 27 May resulting in losses exceeding $5 million. ...

10 July 2026 · ZX Cloud Security

CVE-2026-48939: iCagenda File Upload RCE Flaw

🔴 Critical | Source: CISA Known Exploited Vulnerabilities A critical vulnerability in the iCagenda Joomla extension allows attackers to upload arbitrary files — including PHP scripts — via the file attachment feature, enabling remote code execution on the hosting server. This flaw has been confirmed as actively exploited and added to CISA’s Known Exploited Vulnerabilities catalogue, with a remediation deadline of 13 July 2026. Any site running iCagenda is at risk of full server compromise if left unpatched. ...

10 July 2026 · ZX Cloud Security

CVE-2026-56291: Balbooa Forms RCE via File Upload

🔴 Critical | Source: CISA Known Exploited Vulnerabilities A critical vulnerability in Balbooa Forms allows unauthenticated attackers to upload executable files to affected servers, leading to full remote code execution (RCE). The flaw requires no login or privileges to exploit, making it trivially accessible to any attacker who can reach the application. It has been added to CISA’s Known Exploited Vulnerabilities catalogue, confirming active exploitation in the wild. Security Architect’s Take: Identify any internet-facing deployments of Balbooa Forms within your environment or those of managed tenants and apply vendor patches immediately — the CISA remediation deadline is 13 July 2026. If patching cannot be completed promptly, restrict public access to the forms endpoint via WAF rules or network controls and implement file upload scanning to block executable content. ...

10 July 2026 · ZX Cloud Security

Ubiquiti UniFi Critical Flaws: CVE-2026-50746 Patched

🔴 Critical | Source: The Hacker News Ubiquiti has released patches addressing multiple critical vulnerabilities across its UniFi product suite, including Connect, Talk, Access, Protect, and OS. The most severe flaw, CVE-2026-50746, carries a perfect CVSS score of 10.0 and involves improper access control in UniFi Connect. Successful exploitation could allow attackers to escalate privileges or execute arbitrary commands on affected devices. Security Architect’s Take: Prioritise immediate patching of all UniFi devices across your estate — a CVSS 10.0 with privilege escalation and command execution potential means these are effectively pre-auth or low-barrier takeover risks. Audit your network segmentation to ensure UniFi management interfaces are not exposed to untrusted networks or the public internet whilst patching is in progress. ...

8 July 2026 · ZX Cloud Security

GhostLock CVE-2026-43499: Linux Root & Container Escape

🔴 Critical | Source: The Hacker News A 15-year-old Linux kernel vulnerability, dubbed GhostLock (CVE-2026-43499), allows any locally authenticated user to gain full root privileges and escape container boundaries without requiring special permissions or unusual configurations. The flaw has been present by default in virtually every mainstream Linux distribution since 2011, making the potential attack surface enormous. Because no network access is needed, the risk is particularly acute in multi-tenant environments such as shared cloud instances and Kubernetes nodes. ...

8 July 2026 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options