View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

Critical RCE Flaw in Azure Cosmos DB with CVSS 10.0

๐Ÿ’ฅ BREACHES & INCIDENTS

  • CareCloud notifies 345,000+ after March breach exposed medical records CareCloud suffered a data breach exposing medical records of over 345,000 people.
    • Applies to CareCloud, a U.S. health tech company serving 45,000+ providers
    • Hackers accessed one electronic health record data store hosted on AWS
    • Breach lasted at least six days in March 2026, from March 10 to March 16
    • Stolen data includes names, addresses, Social Security numbers, IDs, financial and medical info
    • No ransomware group has claimed responsibility; breach disclosed to multiple state AGs ๐Ÿ“Ž Coverage: techcrunch.com ยท ๐Ÿ‘ via @zackwhittaker@mastodon.social

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • Critical Remote Code Execution Flaw Discovered in Azure Cosmos DB (CVE-2026-66803) CVE-2026-66803 Azure Cosmos DB has a critical remote code execution vulnerability due to improper access control.

    • Applies to Azure Cosmos DB cloud database service
    • Vulnerability allows unauthorized remote code execution
    • Exploited via network without requiring privileges or user interaction
    • Severity rated critical with CVSS score 10.0
    • Root cause is improper access control (CWE-284) ๐Ÿ“Ž Coverage: cve.threatint.com ยท ๐Ÿ“„ Original: cve.threatint.com ยท ๐Ÿ‘ via CVE ThreatInt
  • Coordinated Cyberattacks Disrupt 30+ Minnesota Water Utilities' PLCs Iran-linked hackers coordinated cyberattacks on over 30 Minnesota water utilities' PLCs.

    • Targets: More than 30 Minnesota community water and wastewater utilities
    • Vulnerabilities: Internet-exposed programmable logic controllers (PLCs), including Rockwell Automation MicroLogix 1400
    • Attack method: Remote intrusions modifying PLC passwords, changing IP addresses, disrupting automated controls
    • Impact: Temporary operational disruptions, manual operations, boil water notices avoided
    • Attribution: Linked to Iranian-affiliated threat groups like CyberAv3ngers and Handala, per state fusion center report ๐Ÿ“Ž Coverage: securityweek.com ยท ๐Ÿ“„ Original: csoonline.com ยท ๐Ÿ‘ via SecurityWeek, Dark Reading (+2)

๐Ÿ“‹ ADVISORIES

  • JetBrains warns of critical remote code execution flaw in TeamCity On-Premises JetBrains disclosed a critical authentication bypass vulnerability in TeamCity On-Premises enabling remote code execution.
    • Affects all versions of TeamCity On-Premises; TeamCity Cloud not impacted
    • Vulnerability CVE-2026-63077 allows attackers with HTTPS access to bypass authentication
    • Exploitation via agent polling protocol enables arbitrary OS command execution with server privileges
    • Disclosed July 27, 2026; no evidence of active exploitation at disclosure
    • Patch available in TeamCity 2025.11.7, 2026.1.3, and as a plugin for versions 2017.1+ ๐Ÿ“Ž Coverage: bleepingcomputer.com ยท ๐Ÿ‘ via BleepingComputer

๐Ÿ”“ CVEs & KEV

  • Other: 19 CVEs (worst 8.8)

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check