CVE-2026-63077: Critical TeamCity RCE Flaw

🔴 Critical | Source: The Hacker News A critical vulnerability (CVE-2026-63077, CVSS 9.8) in JetBrains TeamCity On-Premises allows unauthenticated attackers to execute arbitrary operating system commands. All on-premises versions are affected, with fixes available in versions 2025.11.7 and 2026.1.3. TeamCity is widely used in CI/CD pipelines, making this a significant supply chain risk for organisations that have not yet patched. Security Architect’s Take: Patch all TeamCity On-Premises instances to version 2025.11.7 or 2026.1.3 immediately — unauthenticated RCE on a CI/CD platform represents a critical supply chain exposure. If patching is not immediately possible, restrict network access to TeamCity servers to trusted IP ranges and audit recent build logs for signs of unauthorised command execution. ...

28 July 2026 · ZX Cloud Security

CVE-2026-16812: Arista VeloCloud Orchestrator Exploited

🔴 Critical | Source: The Hacker News A critical command injection vulnerability (CVE-2026-16812, CVSS 10.0) in on-premises Arista VeloCloud Orchestrator is being actively exploited in the wild, allowing attackers to execute arbitrary operating system commands. VeloCloud Orchestrator is a SD-WAN management platform widely used to control network connectivity across enterprise and cloud environments. Active exploitation means unpatched deployments are at immediate risk of full system compromise. Security Architect’s Take: Prioritise emergency patching of all on-premises VeloCloud Orchestrator instances immediately, and in the interim restrict management-plane access to trusted IP ranges via firewall rules or a jump host — do not expose the VCO admin interface directly to the internet. ...

28 July 2026 · ZX Cloud Security

vBulletin Pre-Auth RCE Exploit Released – Patch Now

🔴 Critical | Source: The Hacker News A public exploit has been released for a patched remote code execution vulnerability in vBulletin forum software, allowing an unauthenticated attacker to execute arbitrary code by reaching PHP’s eval() function without any account or user interaction. Affected versions include vBulletin 6.2.1 and earlier, and 6.1.6 and earlier. The public availability of working exploit code significantly raises the risk for any unpatched installations. Security Architect’s Take: Audit your environment immediately for any internet-facing vBulletin instances and confirm they are running a patched version; if patching cannot be done immediately, place a WAF rule blocking the known exploit request pattern and consider taking the forum offline until remediation is complete. ...

27 July 2026 · ZX Cloud Security

CVE-2025-68686: Fortinet FortiOS Patch Bypass Flaw

🔴 Critical | Source: CISA Known Exploited Vulnerabilities A vulnerability in Fortinet FortiOS allows remote unauthenticated attackers to bypass a previously issued patch designed to address a symbolic link persistence mechanism used in post-exploitation scenarios. An attacker must have already compromised the device at the filesystem level via a separate vulnerability to exploit this flaw. Its presence on the CISA KEV catalogue confirms active exploitation in the wild, making prompt remediation essential. ...

27 July 2026 · ZX Cloud Security

CVE-2026-16812: Arista VeloCloud Orchestrator RCE Flaw

🔴 Critical | Source: CISA Known Exploited Vulnerabilities A critical OS command injection vulnerability in Arista VeloCloud Orchestrator (VCO) On-Prem allows a remote attacker to execute privileged commands on the host system without authentication. Successful exploitation could give an attacker full control over the orchestrator, compromising all SD-WAN network management, configuration data, and connected infrastructure. This is actively exploited according to CISA, with remediation required by 30 July 2026. Security Architect’s Take: Immediately audit all internet-exposed VeloCloud Orchestrator instances and apply Arista’s patch or mitigation — if patching is not yet possible, restrict management plane access to trusted IP ranges via firewall rules and review VCO audit logs for anomalous command execution or privilege escalation activity. ...

27 July 2026 · ZX Cloud Security

CVE-2026-16723: Fastjson 1.x RCE Exploited, No Patch

🔴 Critical | Source: The Hacker News A critical remote code execution vulnerability (CVE-2026-16723) in Fastjson 1.x, Alibaba’s widely-used Java JSON library, is being actively exploited in the wild with no patch currently available. Attackers can send a crafted JSON request to vulnerable Spring Boot applications and execute arbitrary code without authentication, inheriting the full privileges of the Java process. The absence of a fix makes this particularly dangerous for any organisation running Fastjson 1.x in production. ...

25 July 2026 · ZX Cloud Security

GitLab RCE PoC: Patch Self-Managed Instances Now

🔴 Critical | Source: The Hacker News A working proof-of-concept exploit has been published for a remote code execution flaw in GitLab, allowing any authenticated user with push access to run arbitrary commands as the ‘git’ system user on unpatched self-managed instances. The vulnerability is triggered by committing a specially crafted Jupyter notebook and viewing its diff, which leaks heap memory and enables code execution. GitLab patched the flaw on 10 June, but any self-managed instance still running version 18.11.3 without the update is directly at risk. ...

25 July 2026 · ZX Cloud Security

Cl0p Exploiting PTC Windchill & FlexPLM RCE Flaws

🔴 Critical | Source: The Hacker News Affiliates of the Cl0p ransomware group are actively exploiting vulnerabilities in PTC Windchill and FlexPLM, two widely used product lifecycle management platforms. Attackers chain a pre-authentication information disclosure flaw in FlexPLM’s WSDL endpoint with a server-side vulnerability in the Windchill login servlet to achieve unauthenticated remote code execution. Any organisation with internet-exposed instances of these products is at immediate risk of data theft and extortion. ...

25 July 2026 · ZX Cloud Security

Certighost: Low-Priv AD Users Can Impersonate Domain Control

🔴 Critical | Source: The Hacker News A working exploit named Certighost allows any low-privileged Active Directory user to obtain a certificate impersonating a Domain Controller, then use that certificate to authenticate as the DC via Kerberos. Because Domain Controllers hold directory replication privileges, an attacker can leverage this to run a DCSync attack and extract the krbtgt password hash, effectively compromising the entire domain. Published exploit code is already publicly available, making this an immediate operational risk. ...

24 July 2026 · ZX Cloud Security

ChatGPT AgentForger Flaw: Rogue AI Agents via Phishing

🔴 Critical | Source: The Hacker News A critical vulnerability dubbed AgentForger, discovered by Zenity Labs in OpenAI’s ChatGPT Workspace Agents, could have allowed an attacker to silently create, authorise, and deploy a rogue AI agent inside a victim’s organisation using nothing more than a phishing link. The flaw required no elevated access beyond tricking a user into clicking a malicious URL, giving attackers a stealthy foothold within enterprise AI workflows. OpenAI patched the issue on 8 June 2026. ...

24 July 2026 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options