CVE-2026-47302: .NET Denial of Service Vulnerability

🟠 High | Source: Microsoft Security Response Center CVE-2026-47302 is a denial of service vulnerability in Microsoft .NET caused by unbounded resource allocation — meaning an attacker can exhaust server resources without needing to authenticate. This can render applications and services built on .NET unavailable. It is exploitable remotely over a network, making it a meaningful risk for any internet-facing .NET workloads. Security Architect’s Take: Audit your Azure and on-premises workloads for exposed .NET applications and prioritise patching to the fixed .NET runtime version as soon as it is available. In the interim, consider placing rate-limiting controls or a WAF in front of vulnerable endpoints to reduce exposure. ...

14 July 2025 · ZX Cloud Security

CVE-2026-47303: ASP.NET Core Privilege Escalation

🟠 High | Source: Microsoft Security Response Center A vulnerability in ASP.NET Core allows an already-authenticated attacker to gain higher privileges than they should have by exploiting data that the application incorrectly assumes cannot be changed. This means an attacker with limited access could potentially escalate to broader control over affected systems or resources. Applications hosted on Azure or any cloud environment running ASP.NET Core are at risk if left unpatched. ...

14 July 2025 · ZX Cloud Security

CVE-2026-48571: Windows App Installer Privilege Escalation

🟠 High | Source: Microsoft Security Response Center CVE-2026-48571 is a use-after-free vulnerability in the Windows App Package Installer (AppX Installer) that allows a locally authenticated attacker to elevate their privileges on the affected system. This type of memory corruption flaw can be exploited to gain higher-level access than originally granted, potentially enabling full system compromise. It is particularly relevant in cloud environments where Windows virtual machines or Azure Virtual Desktop instances are in use. ...

14 July 2025 · ZX Cloud Security

CVE-2026-48572: Windows App Installer Privilege Escalation

🟠 High | Source: Microsoft Security Response Center A race condition vulnerability in the Windows App Package Installer (AppX Installer) allows a locally authenticated attacker to elevate their privileges on the affected system. Race conditions of this type exploit timing gaps between security checks and resource access, making them tricky to detect. This is particularly relevant in cloud environments where Windows virtual machines or Azure Virtual Desktop deployments may be exposed to multi-user or shared workloads. ...

14 July 2025 · ZX Cloud Security

CVE-2026-49162: Microsoft Brokering File System EoP

🟠 High | Source: Microsoft Security Response Center CVE-2026-49162 is a use-after-free vulnerability in the Microsoft Brokering File System, a Windows component that facilitates file access between sandboxed applications and the broader system. An attacker who already has local access can exploit this flaw to gain elevated privileges on the affected machine. This is particularly relevant in cloud environments where Windows VMs or Azure Virtual Desktop sessions may be shared or accessed by multiple users. ...

14 July 2025 · ZX Cloud Security

CVE-2026-49166: Windows Print Driver Privilege Escalation

🟠 High | Source: Microsoft Security Response Center A use-after-free vulnerability in Microsoft Windows printer drivers allows a locally authenticated attacker to gain elevated privileges on the affected system. Tracked as CVE-2026-49166, the flaw requires the attacker to already have local access but could enable them to move from a standard user account to higher system-level privileges. This is particularly relevant in shared or multi-user Windows environments, including cloud-hosted virtual machines. ...

14 July 2025 · ZX Cloud Security

CVE-2026-49167: Windows Kernel Privilege Escalation

🟠 High | Source: Microsoft Security Response Center CVE-2026-49167 is a use-after-free vulnerability in the Windows Kernel that allows an attacker who already has local access to a machine to elevate their privileges to a higher level, potentially gaining full system control. Although exploitation requires prior authorised access, this type of flaw is frequently chained with other vulnerabilities to achieve full compromise. It is particularly relevant to cloud environments where Windows-based virtual machines, Azure VMs, or hybrid-joined endpoints are in use. ...

14 July 2025 · ZX Cloud Security

CVE-2026-49168: Storage Spaces Direct Privilege Escalation

🟠 High | Source: Microsoft Security Response Center CVE-2026-49168 is an integer overflow vulnerability in Windows Storage Spaces Direct, a feature used in Azure Stack HCI and Windows Server clusters for software-defined storage. It allows an attacker with physical access to a machine to exploit the flaw and gain elevated privileges on the system. Whilst physical access is a prerequisite — limiting opportunistic remote exploitation — the risk is significant in shared or co-located infrastructure environments. ...

14 July 2025 · ZX Cloud Security

CVE-2026-49169 Windows DNS Server RCE Vulnerability

🟠 High | Source: Microsoft Security Response Center A use-after-free vulnerability in Windows DNS Server allows an authenticated attacker to remotely execute arbitrary code over a network. Although exploitation requires some level of authorisation, DNS Server is a critical infrastructure component widely deployed across Windows environments, making the blast radius significant. Successful exploitation could allow an attacker to fully compromise the affected server. Security Architect’s Take: Prioritise patching Windows DNS Server instances immediately, particularly those exposed internally to broad network segments or running on domain controllers. Where patching cannot be applied immediately, consider restricting DNS management plane access via network controls and monitoring for anomalous DNS Server process behaviour. ...

14 July 2025 · ZX Cloud Security

RabbitMQ OAuth Secret Leak & Cross-Tenant Flaw

🟠 High | Source: The Hacker News Two access control vulnerabilities in the RabbitMQ message broker have been disclosed that could allow attackers to steal OAuth client secrets and access queue metadata belonging to other tenants. The flaws, discovered by Miggo’s security team, expose organisations using RabbitMQ for enterprise messaging to potential infrastructure takeover and cross-tenant data leakage. This is particularly concerning in multi-tenant deployments where strict isolation between customers or business units is expected. ...

14 July 2025 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options