BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Critical Arista VeloCloud Flaw Under Active Attack, Patch Now

Active exploitation of critical Arista VCO, Fortinet, and Alibaba Fastjson flaws.

  • A maximum-severity command injection flaw (CVE-2026-16812, CVSS 10.0) in on-premises Arista VeloCloud Orchestrator (VCO) is under active exploitation.
  • CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog, requiring federal agencies to patch by July 30, 2026.
  • Additional vulnerabilities under active attack include a Fortinet FortiOS SSL-VPN flaw (CVE-2025-68686) and an unpatched critical issue in Alibaba’s Fastjson library (CVE-2026-16723).

A critical remote code execution vulnerability in on-premises versions of Arista VeloCloud Orchestrator (VCO) is being actively exploited in the wild as of July 28, 2026. Tracked as CVE-2026-16812 and holding the maximum CVSS score of 10.0, the operating system command injection flaw allows a remote attacker to access privileged internal functionality. Arista stated that successful exploitation could compromise the orchestrator’s confidentiality, integrity, and availability.

- Advertisement -

The issue was already addressed in hosted and dedicated VCO versions, but multiple on-premises releases remain vulnerable, including all versions of VCO 5.2.x prior to 5.2.3.14. While Arista acknowledged the flaw was externally discovered and actively exploited, it did not disclose how many customers were impacted. As indicators of compromise, the company shared three IP addresses linked to the attacks: 8.19.75.217, 206.72.242.124, and 206.72.242.162.

Arista warned that compromises to the VCO platform could grant attackers access to VeloCloud Edge devices as well. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the flaw to its Known Exploited Vulnerabilities catalog, requiring Federal Civilian Executive Branch agencies to apply patches by July 30, 2026.

Meanwhile, CISA also added a medium-severity vulnerability in Fortinet FortiOS SSL-VPN (CVE-2025-68686, CVSS 5.3) to its catalog, citing active exploitation evidence. Fortinet said an attacker would first need to compromise the product via another vulnerability, with federal agencies given until August 10, 2026, to patch.

Another security flaw under attack is CVE-2026-16723 (CVSS 9.0), a critical unpatched issue in Alibaba’s Fastjson library that enables remote code execution. Developers using versions 1.2.68 through 1.2.83 are urged to enable SafeMode or switch to a non-impacted build immediately.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Musk: AI to surpass human intelligence in 5 years

Elon Musk predicts AI will surpass the combined intelligence of humanity within about five...

Gate.io accused of stalling $1.7M crypto theft probe

User "Jheioff" accuses Gate.io of withholding video and risk-control data from police after a...

Bitmine adds 10k ETH, holdings now 5.79M Ether

Bitmine Immersion Technologies now holds 5.79 million Ether, representing about 4.8% of the total...

Dysphoria botnet uses blockchain to evade takedown after police raid

The Dysphoria IoT botnet, tracked by CNCERT and XLab, now uses Ethereum Name Service...

Claude share links indexed by Google, exposing private data

A Reddit user discovered on July 25 that a Google search for shared Claude...

Must Read

The Best Bitcoin Casinos of 2025: An Expert’s Data-Driven Guide

Top 3 Bitcoin Casinos - Quick Comparison ...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading