CVE-2026-45461: MS Office Android RCE Vulnerability

🟠 High | Source: Microsoft Security Response Center A remote code execution vulnerability (CVE-2026-45461) has been identified in Microsoft Office for Android. An attacker exploiting this flaw could execute arbitrary code on a victim’s device, potentially leading to full device compromise. Microsoft has released a security update and users should apply it immediately. Security Architect’s Take: Ensure your mobile device management (MDM) policy enforces automatic updates for Microsoft Office on Android devices, and verify compliance across your fleet via Intune or equivalent tooling. Consider temporarily restricting Office for Android access on unmanaged or non-compliant devices until the patch is confirmed deployed. ...

19 June 2025 · ZX Cloud Security

CVE-2026-45469: Excel for Mac RCE Vulnerability

🟠 High | Source: Microsoft Security Response Center A remote code execution vulnerability (CVE-2026-45469) has been identified in Microsoft Excel for Mac. An attacker exploiting this flaw could execute arbitrary code on an affected system, potentially gaining full control. Only users running Microsoft Office on macOS are affected; other platforms do not require action. Security Architect’s Take: Ensure macOS endpoints running Microsoft Office are patched immediately via the update referenced in the release notes. If you manage a fleet of Mac devices through MDM (e.g. Jamf or Intune), prioritise deploying this update and confirm compliance before end of the current patching cycle. ...

19 June 2025 · ZX Cloud Security

CVE-2026-45471: Microsoft Word RCE for Mac Fix

🟠 High | Source: Microsoft Security Response Center A remote code execution vulnerability (CVE-2026-45471) has been identified in Microsoft Word, affecting Microsoft Office for Mac users. An attacker who successfully exploits this flaw could execute arbitrary code on a victim’s machine. Microsoft has released security updates and only Mac users running affected Office software need to act. Security Architect’s Take: Ensure macOS endpoints running Microsoft Office are patched immediately via your MDM or endpoint management tooling; verify compliance through your vulnerability management platform and confirm no affected versions remain in your fleet, particularly on devices with access to cloud-hosted resources or sensitive data. ...

19 June 2025 · ZX Cloud Security

CVE-2026-45472: Microsoft Office Android RCE Patch

🟠 High | Source: Microsoft Security Response Center A remote code execution vulnerability (CVE-2026-45472) has been identified in Microsoft Office for Android, allowing an attacker to potentially execute arbitrary code on a user’s device. Microsoft has released a security update to address the flaw, and users running affected versions should apply the patch immediately. While this affects a mobile application rather than a cloud service directly, compromised devices accessing corporate cloud resources pose a significant risk to enterprise environments. ...

19 June 2025 · ZX Cloud Security

CVE-2026-45474 Microsoft Office Android RCE Flaw

🟠 High | Source: Microsoft Security Response Center A remote code execution vulnerability (CVE-2026-45474) has been identified in Microsoft Office for Android, allowing an attacker to potentially execute arbitrary code on a target device. Microsoft has released a security update to address the flaw, and affected users must install it to be protected. Unpatched devices running Microsoft Office for Android remain at risk of compromise. Security Architect’s Take: Ensure your mobile device management (MDM) or MAM policy enforces the latest Microsoft Office for Android update across all managed and BYOD devices; consider blocking access to corporate resources from devices running outdated Office versions until patched. ...

19 June 2025 · ZX Cloud Security

CVE-2026-45486: Microsoft Word RCE Flaw for Mac

🟠 High | Source: Microsoft Security Response Center A remote code execution vulnerability (CVE-2026-45486) has been identified in Microsoft Word for Mac. An attacker exploiting this flaw could execute arbitrary code on an affected machine, potentially leading to full system compromise. Only users running Microsoft Office for Mac are affected; other Office platforms require no action. Security Architect’s Take: Ensure all Mac endpoints running Microsoft Office are updated immediately via your MDM or patch management tooling. Validate compliance through your endpoint management platform and consider blocking macro execution or untrusted document sources as an interim control. ...

19 June 2025 · ZX Cloud Security

CVE-2026-45643: Microsoft Word RCE Vulnerability for Mac

🟠 High | Source: Microsoft Security Response Center A remote code execution vulnerability (CVE-2026-45643) has been identified in Microsoft Word affecting Mac users running specific versions of Microsoft Office for Mac. An attacker exploiting this flaw could execute arbitrary code on a victim’s machine, potentially leading to full system compromise. Only Mac users of affected Office versions need to act; other platforms are unaffected. Security Architect’s Take: Ensure your macOS endpoint management tooling (e.g. Intune, Jamf) has deployed the latest Microsoft Office for Mac update across all managed devices promptly. Verify compliance reporting confirms patched versions before considering the risk mitigated. ...

19 June 2025 · ZX Cloud Security

Texas Vendor Breach Exposes 3M Hunters & Anglers

🟠 High | Source: The Register — Security A third-party vendor breach has exposed the personal data of approximately 3 million Texas residents who hold hunting and fishing licences. The incident highlights the ongoing risk posed by state government agencies relying on external vendors to process and store citizen data. While full details of the compromised data types are still emerging, breaches of this scale affecting public-sector licence systems typically expose names, addresses, dates of birth, and contact information. ...

19 June 2025 · ZX Cloud Security

Shadow AI: The Access Control Risk You're Ignoring

🟠 High | Source: The Hacker News Shadow AI has evolved beyond simple data leakage risks into a more complex access control problem, where unsanctioned AI tools acquire and retain permissions to enterprise systems and data. Employees connecting AI agents to corporate resources create persistent access paths that bypass traditional identity and access management controls. This represents a significant governance gap that most organisations’ current security tooling is not equipped to detect or remediate. ...

19 June 2025 · ZX Cloud Security

Salesforce Disables Klue App After OAuth Token Abuse

🟠 High | Source: The Hacker News Salesforce has disabled the Klue Battlecards app integration after a security incident on 11 June 2026 in which OAuth tokens were abused to expose customer data. The breach originated at Klue, a competitive intelligence platform, but impacted organisations using its Salesforce integration. Affected customers cannot reconnect the integration until Salesforce deems it safe to reinstate. Security Architect’s Take: Audit all third-party OAuth app integrations in your Salesforce org immediately — revoke tokens for any apps you do not actively use or cannot verify, and review Salesforce’s connected app logs for anomalous access patterns. This incident is a reminder to enforce least-privilege OAuth scopes and implement periodic token rotation policies for ISV integrations. ...

19 June 2025 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options