Network-Appliance
CVE-2026-16812: Max-Severity Command Injection in Arista VeloCloud Orchestrator, Actively Exploited — CISA Sets July 30 Deadline
An unauthenticated OS command injection flaw (CVSS 10.0) in on-premises Arista VeloCloud Orchestrator is under active exploitation. CISA added it to the KEV catalog on July 27 with a July 30 remediation deadline for federal agencies.
A Third NGINX Heap Overflow in Two Months: CVE-2026-42533 Hits the map Directive
F5 patched CVE-2026-42533, a CVSS 9.2 unauthenticated heap buffer overflow in NGINX's script engine reachable through the map directive's regex handling, plus two lower-severity sibling bugs — all landing in Ingress Controller, Gateway Fabric, and App Protect WAF.
CVE-2026-16232: Check Point SmartConsole Auth Bypass Grants Full Admin — Actively Exploited, Added to CISA KEV
An unauthenticated attacker can steal a SmartConsole application login token and log into Check Point's Security Management Server with full admin rights. CVE-2026-16232 (CVSS 9.3) is under active exploitation and now sits in CISA's KEV catalog with a July 25 remediation deadline.
CVE-2026-50522: SharePoint RCE Under Active Exploitation, Attackers Stealing Machine Keys for Post-Patch Persistence
CVE-2026-50522, a critical 9.8 CVSS SharePoint deserialization RCE, is being actively exploited to steal machine keys that let attackers forge auth tokens and keep access even after the box is patched.
CVE-2026-50518: Unauthenticated Heap Overflow RCE in Windows DHCP Server, No Exploit Required to Care
CVE-2026-50518 is a CVSS 9.8 heap-based buffer overflow in Windows DHCP Server, exploitable pre-auth over the network with no user interaction. Microsoft rates it Exploitation More Likely.
Six Bulletins, One Bug Class: What Ubiquiti's 2026 UniFi Cadence Reveals About Shared-OS Edge Platforms
Since October 2025, Ubiquiti has shipped six security bulletins covering the UniFi line — five of them containing CVSS 9.9-10.0 flaws, two of them the exact same shell-injection bug class shipped seven months apart. This is what happens when one Nginx gateway and one OS layer sit in front of your network, your cameras, and your door locks.
VMSA-2026-0005: Seven Flaws in VMware Avi Load Balancer, Topped by a 9.8 Auth Bypass
Broadcom patched seven vulnerabilities in VMware Avi Load Balancer, led by CVE-2026-47865, a CVSS 9.8 authentication bypass that gives a network attacker a foothold on the control plane.
HollowByte: An 11-Byte TLS Handshake Payload That Bloats OpenSSL Server Memory
A memory-allocation flaw in OpenSSL's TLS handshake parsing, dubbed HollowByte, lets an unauthenticated attacker exhaust server memory with an 11-byte payload per connection. No CVE was assigned; patched in 4.0.1 and backported across the 3.x line.
AA26-194A: NSA, CISA, FBI Warn Russian FSB Center 16 Is Harvesting Router Configs via Weak SNMP and an 18-Year-Old Cisco CSRF Bug
A 19-agency joint advisory (AA26-194A) details a years-long Russian FSB Center 16 campaign that scans for default SNMP community strings and an 18-year-old Cisco IOS CSRF flaw (CVE-2008-4128, now in CISA KEV) to exfiltrate router configs and pivot into critical infrastructure.
CVE-2026-58658: GPUStack Worker Ports Leaked LLM Prompts and Completions With No Authentication
GPUStack, an open-source GPU cluster manager for vLLM/SGLang/TensorRT-LLM inference, shipped worker debug and log-streaming endpoints with zero authentication — letting anyone who can reach the worker port read live prompts, completions, and memory profiles.
CVE-2026-15409 & CVE-2026-15410: SonicWall SMA1000 Zero-Days Chained for Unauthenticated RCE, CISA Deadline July 17
Two SonicWall SMA1000 zero-days — a CVSS 10.0 SSRF and a post-auth code injection flaw — are being chained in the wild for unauthenticated remote code execution. CISA KEV deadline is July 17, 2026.
Six U-Boot Flaws Let Malicious Firmware Images Execute Code Before Signature Verification Ever Runs
Binarly found six bugs in U-Boot's FIT image parser — two lead to code execution, four to denial of service — and all six trigger while the bootloader is still reading an untrusted image, before it checks the signature that's supposed to protect it.
Progress Tells ShareFile Customers to Power Down Storage Zone Controllers Over 'Credible' Threat
Progress Software is telling on-prem ShareFile Storage Zone Controller admins to physically shut down their Windows servers over an unnamed 'credible external security threat' — no CVE, no patch, no explanation.
Zimbra Patches Classic Web Client Stored XSS Reported by Google TAG
Zimbra shipped 10.1.19 to fix an unauthenticated stored XSS in the Classic Web Client, reachable by simply opening a crafted email — no CVE assigned yet, reported by Google's Threat Analysis Group.
Ubiquiti's Bulletin 066: A CVSS 10.0 in UniFi Connect Leads 25 Flaws Across the Whole UniFi Line
Ubiquiti Security Advisory Bulletin 066 discloses 25 vulnerabilities across UniFi Connect, Talk, Access, Protect, and UniFi OS — headlined by CVE-2026-50746, a CVSS 10.0 unauthenticated command injection reachable on ~100,000 internet-facing endpoints.
CVE-2026-11405: Undocumented Admin Backdoor in Tenda Router Firmware, No Patch Available
CERT/CC disclosed a hardcoded backdoor password mechanism in Tenda router firmware that grants full admin access regardless of the real password — Tenda has not responded to coordination attempts since May, and there is no patch.
SimpleHelp OIDC Auth Bypass (CVE-2026-48558) Under Active Exploitation, Deploying Djinn Stealer Against Dev Credentials
A critical unsigned-token flaw in SimpleHelp RMM's OIDC login is being exploited to plant a cross-platform infostealer that hunts for cloud, source-control, and AI-assistant credentials.
Adobe ColdFusion APSB26-68: Six CVSS 10.0 Flaws, and Exploitation Started Within Hours
Adobe's APSB26-68 bulletin patches 11 ColdFusion flaws — six rated CVSS 10.0 — including a Remote Development Services path-traversal bug (CVE-2026-48282) that attackers began probing within hours of disclosure.
CVE-2026-8451: A New CitrixBleed-Pattern Memory Overread Is Already Under Active Exploitation
Citrix patched CVE-2026-8451, a pre-auth memory overread in NetScaler's SAML IdP parser that leaks session tokens — and attackers were already exploiting it within 24 hours of disclosure.
CVE-2026-8037: Pre-Auth Root RCE in Progress Kemp LoadMaster Now Under Active Exploitation
CVE-2026-8037, a CVSS 9.8 uninitialized-heap flaw in Progress Kemp LoadMaster's escape_quotes() function, lets unauthenticated attackers run root commands on the load balancer's management API. eSentire observed exploitation attempts starting June 29.