CVE-2026-53359: Linux KVM Guest VM Escape Flaw

🔴 Critical | Source: The Hacker News A 16-year-old use-after-free vulnerability in the Linux KVM hypervisor (CVE-2026-53359), dubbed ‘Januscape’, allows a guest virtual machine to corrupt host kernel memory and potentially escape its isolation boundary. The flaw affects both Intel and AMD x86 systems via shared shadow MMU code. A public proof-of-concept already causes host kernel panics, and the researcher claims a full working exploit exists but has not been released. ...

6 July 2026 · ZX Cloud Security

CVE-2026-20896: Gitea Docker Auth Bypass Exploited

🔴 Critical | Source: The Hacker News A critical vulnerability (CVE-2026-20896, CVSS 9.8) in Gitea Docker images allows unauthenticated attackers to gain elevated privileges by spoofing the X-WEBAUTH-USER HTTP header, which Gitea trusts from any source IP. Active exploitation attempts have been observed just 13 days after public disclosure, indicating rapid uptake by threat actors. Organisations running Gitea in Docker environments are at immediate risk of full account takeover without requiring any credentials. ...

6 July 2026 · ZX Cloud Security

CVE-2026-46242: Bad Epoll Linux Root Exploit

🔴 Critical | Source: The Hacker News A Linux kernel vulnerability dubbed ‘Bad Epoll’ (CVE-2026-46242) allows an unprivileged local user to escalate privileges to root, giving them full control of an affected system. It impacts Linux desktops, servers, and Android devices. A patch has been released, making rapid remediation the immediate priority. Security Architect’s Take: Prioritise patching Linux hosts and Android-based endpoints — particularly cloud workloads running on Linux VMs or containers — to the latest kernel version addressing CVE-2026-46242. Assess your attack surface for any multi-tenant or shared environments where unprivileged user access exists, as local privilege escalation flaws carry the highest risk in those contexts. ...

3 July 2026 · ZX Cloud Security

CVE-2026-56645: Microsoft Edge RCE Vulnerability

🔴 Critical | Source: Microsoft Security Response Center A heap-based buffer overflow vulnerability in Microsoft Edge (Chromium-based) allows an unauthenticated attacker to execute arbitrary code remotely over a network. This type of flaw can be exploited without requiring the victim to take any action beyond having a vulnerable browser version in use. The risk is significant in enterprise environments where Edge is widely deployed, particularly on systems with access to cloud management portals and sensitive resources. ...

3 July 2026 · ZX Cloud Security

CVE-2026-57975: Microsoft Edge RCE Vulnerability

🔴 Critical | Source: Microsoft Security Response Center A type confusion vulnerability in Microsoft Edge (Chromium-based) allows an unauthenticated attacker to execute arbitrary code remotely by exploiting how the browser handles certain resource types. This class of bug is considered high-risk because it can be triggered without user authentication and may require only minimal interaction, such as visiting a malicious webpage. Organisations relying on Edge for cloud console access or web-based tooling face elevated exposure. ...

3 July 2026 · ZX Cloud Security

CVE-2026-57984: Microsoft Edge RCE Vulnerability

🔴 Critical | Source: Microsoft Security Response Center A use-after-free memory vulnerability in Microsoft Edge (Chromium-based) allows a remote, unauthenticated attacker to execute arbitrary code on a victim’s machine over a network. Use-after-free bugs occur when a programme continues to reference memory after it has been freed, which attackers can exploit to hijack execution flow. This is particularly dangerous in a browser context, where visiting a malicious web page or clicking a crafted link could be sufficient to trigger exploitation. ...

3 July 2026 · ZX Cloud Security

CVE-2026-57988: Microsoft Edge RCE Vulnerability

🔴 Critical | Source: Microsoft Security Response Center CVE-2026-57988 is a remote code execution vulnerability in Microsoft Edge (Chromium-based) caused by a relative path traversal flaw. An unauthenticated attacker could exploit this over a network to execute arbitrary code on a victim’s machine. This is particularly concerning in enterprise environments where Edge is widely deployed and users may access cloud management portals or internal tooling through the browser. Security Architect’s Take: Prioritise pushing the patched Edge update across your estate via Intune or your endpoint management tooling immediately, and consider temporarily restricting access to sensitive cloud console URLs (Azure Portal, AWS Console) from unmanaged or unpatched devices using Conditional Access or browser-based device compliance policies. ...

3 July 2026 · ZX Cloud Security

CVE-2026-57992: Microsoft Edge RCE Vulnerability

🔴 Critical | Source: Microsoft Security Response Center CVE-2026-57992 is a use-after-free vulnerability in Microsoft Edge (Chromium-based) that allows an unauthenticated attacker to execute arbitrary code remotely. Use-after-free bugs occur when a programme continues to use memory after it has been freed, which attackers can exploit to hijack execution flow. This is particularly concerning for organisations where Edge is used to access cloud management portals, as a successful exploit could compromise user sessions and credentials. ...

3 July 2026 · ZX Cloud Security

Citrix Bleed 2 CVE-2025-5777 Exploited by Anubis Ransomware

🔴 Critical | Source: The Hacker News The Anubis ransomware group is actively exploiting CVE-2025-5777, dubbed Citrix Bleed 2, to gain initial access to target environments. Affiliates are combining this with Bring Your Own Vulnerable Driver (BYOVD) techniques, supply chain credential theft, and legitimate remote management tooling to move laterally and evade detection. The breadth of tactics across multiple affiliates makes this a significant and evolving threat to enterprise environments running Citrix NetScaler. ...

2 July 2026 · ZX Cloud Security

SharePoint RCE Added to CISA KEV — Patch Now

🔴 Critical | Source: The Register — Security A remote code execution vulnerability in Microsoft SharePoint on-premises servers has been added to CISA’s Known Exploited Vulnerabilities catalogue, meaning it is actively being used in real-world attacks. Exploitation requires only a valid SharePoint account, making the barrier to attack unusually low. Microsoft had previously assessed exploitation as ’less likely’, but CISA’s addition signals that assessment was incorrect and patching is now urgent. ...

2 July 2026 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options