CVE-2026-58253: NATS Server Route API Auth Bypass

🟠 High | Source: Microsoft Security Response Center CVE-2026-58253 is an authentication bypass vulnerability in the NATS Server Route API, which could allow an unauthenticated attacker to interact with internal cluster routing endpoints. NATS is a messaging system used in cloud-native and microservices architectures, including those hosted on Azure. If exploited, this flaw could enable unauthorised access to sensitive message traffic or cluster manipulation. Security Architect’s Take: Audit any Azure-hosted workloads running NATS Server and apply vendor patches immediately; additionally, ensure NATS route ports (typically 6222) are not exposed beyond trusted internal network segments using NSGs or private endpoints. ...

15 July 2025 · ZX Cloud Security

CVE-2026-58209: NATS Server MQTT Filter Bypass

🟠 High | Source: Microsoft Security Response Center CVE-2026-58209 is a vulnerability in NATS Server affecting its MQTT implementation, where retained messages and QoS replay can bypass subscription deny filters. This means that access control rules intended to block certain subscribers from receiving messages may be circumvented, potentially exposing sensitive data to unauthorised clients. It is particularly relevant to Azure-hosted workloads using NATS as a messaging backbone. Security Architect’s Take: Audit any NATS Server deployments — particularly those using MQTT with retained messages or QoS — and apply the vendor patch immediately. Review your subscription deny filter configurations and consider temporarily disabling MQTT retained message functionality until patched instances are confirmed in production. ...

15 July 2025 · ZX Cloud Security

CVE-2026-58252: NATS Server Auth Bypass via Wildcard

🟠 High | Source: Microsoft Security Response Center CVE-2026-58252 is a vulnerability in NATS Server that allows an attacker to bypass subscription authorisation controls by exploiting overlapping wildcard patterns. This means a client could subscribe to subjects they are not permitted to access, potentially exposing sensitive messages flowing through the messaging system. NATS is commonly used in cloud-native and microservices architectures, making this a notable risk for environments where message confidentiality and access control are critical. ...

15 July 2025 · ZX Cloud Security

CVE-2026-58250: NATS Server Pre-Auth Crash via Leafnode

🟠 High | Source: Microsoft Security Response Center CVE-2026-58250 is a vulnerability in NATS Server that allows an unauthenticated attacker to crash the server by sending a double INFO message during the leafnode handshake process — before any authentication takes place. This means no credentials are required to trigger a denial-of-service condition, making it trivially exploitable. Any environment running NATS Server with leafnode connections enabled is potentially at risk of service disruption. ...

15 July 2025 · ZX Cloud Security

CVE-2026-58208: NATS Server WebSocket Crash Flaw

🟠 High | Source: Microsoft Security Response Center A vulnerability in NATS Server allows an attacker to crash WebSocket-only JetStream servers by sending a specially crafted MQTT-over-WebSocket connection request, even before MQTT is explicitly enabled. This denial-of-service flaw means that servers not configured for MQTT remain unexpectedly exposed to MQTT-related attack paths. The impact is service disruption, which could affect messaging infrastructure underpinning cloud-native applications. Security Architect’s Take: Audit any NATS Server deployments — particularly those using WebSocket with JetStream — and apply the relevant patch immediately. Review network perimeter controls to restrict WebSocket endpoint exposure to trusted sources whilst remediation is applied. ...

15 July 2025 · ZX Cloud Security

CVE-2026-58251: NATS Server Queue Subscribe Auth Bypass

🟠 High | Source: Microsoft Security Response Center CVE-2026-58251 is an authorisation bypass vulnerability in NATS Server affecting the Queue Subscribe feature, which allows clients to receive messages from shared queues. An attacker who can connect to a NATS instance may be able to subscribe to queue groups they are not authorised to access, potentially exposing sensitive messages or enabling lateral movement within a messaging infrastructure. This is particularly relevant to Azure-hosted workloads that use NATS as a messaging backbone. ...

15 July 2025 · ZX Cloud Security

CVE-2026-58207: NATS Server Remote Crash via Integer Overflo

🟠 High | Source: Microsoft Security Response Center CVE-2026-58207 is a vulnerability in NATS Server, a messaging system used in cloud-native environments, where an integer overflow in the Connz pagination handler can be triggered remotely to crash the server. An unauthenticated or low-privilege attacker could exploit this to cause a denial of service, disrupting messaging infrastructure that many microservices architectures depend on. The availability impact makes this particularly significant in production environments where NATS is a critical communication backbone. ...

15 July 2025 · ZX Cloud Security

CVE-2026-57219: RabbitMQ OAuth Credential Leak via API

🟠 High | Source: Microsoft Security Response Center A vulnerability in RabbitMQ (CVE-2026-57219) allows unauthenticated attackers to retrieve OAuth 2.0 client credentials via an exposed HTTP API endpoint, but only under certain non-default OAuth 2 configurations. If exploited, an attacker could obtain client credentials and potentially impersonate the RabbitMQ service or gain unauthorised access to connected systems. This is particularly relevant to Azure environments where RabbitMQ is deployed with OAuth 2 integrations. ...

15 July 2025 · ZX Cloud Security

CVE-2026-15028: Libarchive Heap Overflow in Azure

🟠 High | Source: Microsoft Security Response Center CVE-2026-15028 is a heap overflow and out-of-bounds read vulnerability in libarchive, triggered when parsing a TAR archive containing a malformed PAX extended header. Libarchive is a widely used open-source library for reading and writing compressed archives, present in many Linux-based systems and cloud workloads. If exploited, an attacker could potentially cause a crash or execute arbitrary code by supplying a crafted archive file. ...

15 July 2025 · ZX Cloud Security

CVE-2026-39822: Root Escape via Symlink in Azure

🟠 High | Source: Microsoft Security Response Center CVE-2026-39822 is a vulnerability in which an attacker can escape a restricted root directory by combining a symbolic link (symlink) with a trailing slash in path handling within the ‘os’ package. This type of flaw can allow a process to access files or directories outside its intended sandbox, potentially exposing sensitive data or enabling privilege escalation. It is categorised as a high-priority Azure-related advisory by Microsoft. ...

15 July 2025 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options