Find notable cyber news and cases, enriched with sources, timelines, and signals.

Arista VeloCloud Orchestrator security update for CVE-2026-16812

Security Patch Release
First reported
Last updated
Happening score
H score 53
1 unique sources, 1 articles

Summary

Hide ▲

Arista released fixes for on-premises VeloCloud Orchestrator after CVE-2026-16812 was confirmed actively exploited, exposing SD-WAN management systems to remote compromise. The flaw is a maximum-severity 10.0 unauthenticated OS command injection that can reach privileged internal functionality. Affected customers must move to 5.2.3.14, 6.1.3.4, 6.4.2.4, or 7.0.0.1 and later.

Related Happenings

CISA orders federal mitigation of CVE-2026-16812

Public Sector Action
H score34 First: 28.07.2026 01:49 Last: 28.07.2026 01:49 Sources 1

How related: CISA has ordered U.S. federal civilian executive branch agencies to mitigate the vulnerability by Thursday, July 30, 2026, as required by Binding Operational Directive 22-01.

About this happening: CISA ordered U.S. federal civilian executive branch agencies to mitigate CVE-2026-16812 by July 30, 2026, escalating federal response to an actively exploited...

RabbitMQ maintainers security patch release for CVE-2026-57219

Security Patch Release
H score29 First: 14.07.2026 16:48 Last: 14.07.2026 16:48 Sources 1

About this happening: RabbitMQ maintainers released fixed versions for multiple supported release lines, closing two access-control flaws that could expose OAuth client secrets and cross-te...

Cisco security patch release for CVE-2026-20262

Security Patch Release
H score47 First: 15.06.2026 20:12 Last: 15.06.2026 20:12 Sources 1

About this happening: Cisco released security updates for CVE-2026-20262 in Catalyst SD-WAN Manager, covering multiple release trains after the zero-day was exploited to reach root pr...

Cisco Secure Workload REST API patch release (CVE-2026-20223)

Security Patch Release
H score55 First: 22.05.2026 08:36 Last: 22.05.2026 08:36 Sources 1

About this happening: Cisco patched CVE-2026-20223, a CVSS 10.0 Secure Workload REST API flaw that could expose sensitive data and allow configuration changes across tenant boundaries. The upda...

Cisco security patch release for CVE-2026-20184

Security Patch Release
H score44 First: 16.04.2026 14:27 Last: 16.04.2026 14:27 Sources 1

About this happening: Cisco released patches for four critical flaws affecting Identity Services Engine (ISE), ISE-PIC, and Webex Services, closing paths to arbitrary code executi...

Timeline

  1. 28.07.2026 01:49 2 articles · 0h ago

    Arista patches actively exploited VeloCloud Orchestrator command injection flaw

    Initial Disclosure

    Arista patched CVE-2026-16812, an unauthenticated OS command injection flaw in on-premises VeloCloud Orchestrator, after confirming it is being actively exploited; successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and the data it manages. CISA also added the CVE to its Known Exploited Vulnerabilities catalog and directed U.S. federal civilian executive branch agencies to mitigate it by Thursday, July 30, 2026.

    Show sources