CVE-2026-16232: Check Point SmartConsole Auth Bypass

🔴 Critical | Source: CISA Known Exploited Vulnerabilities A critical authentication vulnerability in Check Point SmartConsole allows an unauthenticated remote attacker to steal a login token and gain full administrative access to the network security management platform. SmartConsole is the primary interface for managing Check Point firewalls and security policies, meaning a successful exploit could give attackers complete control over an organisation’s network defences. This vulnerability is actively exploited in the wild, as confirmed by its inclusion in CISA’s Known Exploited Vulnerabilities catalogue. ...

22 July 2026 · ZX Cloud Security

CVE-2026-50522: Microsoft SharePoint RCE Flaw

🔴 Critical | Source: CISA Known Exploited Vulnerabilities A critical deserialization vulnerability in Microsoft SharePoint (CVE-2026-50522) allows an unauthenticated remote attacker to execute arbitrary code over a network without any user interaction. Deserialization flaws of this type are notoriously dangerous as they can be exploited to gain full control of affected servers. CISA has added this to its Known Exploited Vulnerabilities catalogue, confirming active exploitation in the wild. Security Architect’s Take: Patch affected SharePoint instances immediately — CISA’s remediation deadline is 25 July 2026, but given active exploitation you should treat this as urgent. If immediate patching is not possible, consider restricting network access to SharePoint servers, enforcing allowlisting at the perimeter, and reviewing logs for anomalous deserialization activity or unexpected process spawning from SharePoint worker processes. ...

22 July 2026 · ZX Cloud Security

CVE-2026-50522: SharePoint RCE Exploited in Wild

🔴 Critical | Source: The Hacker News A critical remote code execution vulnerability in Microsoft SharePoint Server (CVE-2026-50522, CVSS 9.8) is now being actively exploited following the release of a public proof-of-concept. The flaw stems from insecure deserialisation of untrusted data, allowing an unauthenticated attacker to execute arbitrary code over the network. This follows Microsoft’s July 2026 Patch Tuesday fix, meaning organisations that have not yet patched are at significant risk. ...

21 July 2026 · ZX Cloud Security

Qilin Ransomware Exploits PAN-OS CVE-2026-0257

🔴 Critical | Source: The Hacker News Attackers are exploiting CVE-2026-0257, a high-severity authentication bypass flaw in Palo Alto Networks PAN-OS, to gain initial access to victim networks before deploying Qilin ransomware. Arctic Wolf Labs identified multiple intrusions in June 2026 following this pattern. The vulnerability affects PAN-OS portals and gateways, making it a prime target for ransomware groups seeking an unauthenticated foothold. Security Architect’s Take: If you have internet-facing PAN-OS portals or gateways, verify the patch for CVE-2026-0257 has been applied immediately and review your firewall access logs from June 2026 onwards for signs of unauthorised authentication attempts or lateral movement consistent with Qilin TTPs. ...

21 July 2026 · ZX Cloud Security

Zimbra 10.1.20 Patches SNMP Command Injection & XSS

🔴 Critical | Source: The Hacker News Zimbra has released version 10.1.20 patching nine security vulnerabilities, the most severe being a command injection flaw in its SNMP monitoring component that could allow remote code execution when SNMP notifications are enabled. The release also addresses four cross-site scripting (XSS) vulnerabilities. Zimbra is widely used for enterprise email and collaboration, making unpatched instances a high-value target for attackers. Security Architect’s Take: Prioritise upgrading any internet-facing or internally exposed Zimbra instances to 10.1.20 immediately; if patching is delayed, disable SNMP notifications as a temporary mitigating control and audit Zimbra exposure at your network perimeter. ...

21 July 2026 · ZX Cloud Security

WordPress wp2shell RCE: CVE-2026-63030 & CVE-2026-60137

🔴 Critical | Source: The Hacker News Two critical WordPress vulnerabilities, CVE-2026-63030 and CVE-2026-60137 (collectively dubbed wp2shell), are being actively exploited in the wild. When chained together, they allow unauthenticated attackers to achieve remote code execution and full site compromise without any credentials. Mass scanning activity began almost immediately after a public exploit was released, significantly raising the risk for unpatched WordPress installations. Security Architect’s Take: Audit your organisation’s WordPress estate immediately and apply available patches or mitigations without delay. If you host WordPress on cloud infrastructure (EC2, App Service, Cloud Run, etc.), consider placing WAF rules blocking wp2shell exploit patterns at the edge while patching is carried out, and review web application firewall logs for scanning activity originating from the past 72 hours. ...

21 July 2026 · ZX Cloud Security

CVE-2026-6875: ServiceNow AI Platform RCE Exploited

🔴 Critical | Source: The Hacker News A critical vulnerability in the ServiceNow AI Platform (CVE-2026-6875, CVSS 9.5) is being actively exploited in the wild, allowing unauthenticated attackers to escape the application sandbox and execute arbitrary code. The flaw requires no credentials, significantly lowering the bar for attackers. Patches have been released, but active exploitation means organisations running ServiceNow are at immediate risk. Security Architect’s Take: Prioritise patching CVE-2026-6875 across all ServiceNow instances immediately — active exploitation with no authentication requirement means exposure windows must be minimised to hours, not days. If patching cannot be applied immediately, consider restricting network access to ServiceNow instances to known IP ranges and review logs for anomalous unauthenticated activity. ...

21 July 2026 · ZX Cloud Security

OVH Januscape Bug: Silent Mass Reboots Risk Downtime

🔴 Critical | Source: The Register — Security OVH implemented a patch for a critical vulnerability dubbed ‘Januscape’ by silently backporting a fix into Debian and scheduling mass reboots of customer infrastructure without explicit customer consent. The approach risked unplanned downtime for workloads not tolerant of unexpected restarts. This raises serious questions about cloud provider transparency and customer communication during emergency patching events. Security Architect’s Take: Audit your OVH-hosted workloads immediately to confirm reboot resilience and check whether your instances were affected by this patching cycle. Beyond the immediate fix, review your cloud provider contracts and escalation procedures to ensure you have enforceable notification rights before unscheduled maintenance — and document your recovery posture for critical hypervisor-level vulnerabilities. ...

21 July 2026 · ZX Cloud Security

OVH Januscape Hypervisor Bug: Secret Mass Reboots

🔴 Critical | Source: The Register — Security OVH identified a critical vulnerability in its Januscape hypervisor and rolled out a patch via mass, largely unannounced reboots of customer virtual machines, backporting the fix into Debian without seeking prior customer consent. The approach prioritised rapid remediation but risked unplanned downtime for tenants. The French cloud provider used an Australian region as an initial test environment before wider rollout. Security Architect’s Take: If you run workloads on OVH, audit your service agreements and maintenance notification policies immediately — this incident demonstrates that OVH may apply emergency hypervisor patches without explicit consent or advance warning. Ensure your resilience design accounts for unplanned hypervisor reboots, and establish a direct alerting channel with your OVH account team for critical infrastructure changes. ...

21 July 2026 · ZX Cloud Security

CVE-2026-0770: Langflow RCE Vulnerability Actively Exploited

🔴 Critical | Source: CISA Known Exploited Vulnerabilities CVE-2026-0770 is a critical remote code execution vulnerability in Langflow, an open-source tool used to build AI-powered workflows. The flaw allows attackers to execute arbitrary code on affected systems by abusing untrusted functionality included within the application. It has been added to CISA’s Known Exploited Vulnerabilities catalogue, confirming active exploitation in the wild. Security Architect’s Take: Identify any Langflow instances running in your environment — including developer sandboxes and AI/ML pipelines — and patch immediately or isolate them from public access. Given active exploitation, treat any internet-exposed Langflow deployments as potentially compromised and conduct a thorough investigation before patching. ...

21 July 2026 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options