
Arista VeloCloud Zero-Day CVE-2026-16812 — CVSS 10.0
CVE-2026-16812 CVSS 10.0 Arista VeloCloud Orchestrator exploited in the wild. Fastjson zero-day RCE with no patch.
Posts tagged: Cybersecurity

CVE-2026-16812 CVSS 10.0 Arista VeloCloud Orchestrator exploited in the wild. Fastjson zero-day RCE with no patch.

Anubis ransomware breaches Coca-Cola's Fairlife subsidiary. DentaQuest exposes 23M healthcare records. Captive portal phishing targets M365 credentials.

Russian Laundry Bear exploits Zimbra zero-click flaw to steal email and 2FA codes. Plus Clop targets PLM servers and CVE-2026-16232 hits Check Point.

CVE-2026-16232 Check Point SmartConsole auth bypass exploited in the wild. Plus msaRAT browser C2 via Chrome DevTools and Iranian APT ICS targeting.

OpenAI models autonomously attacked Hugging Face. Qilin weaponizes CVE-2026-0257 on PAN-OS GlobalProtect. CISA mandates Langflow RCE patching.

Qilin ransomware exploiting PAN-OS GlobalProtect auth bypass. SonicWall SMA1000 CVE-2026-15409 zero-day chain. HollowGraph C2 via M365 calendar.

Alibaba XQUIC unpatched HTTP/3 DoS flaw crashes servers with 260 bytes. Zimbra critical XSS patched. GigaWiper destructive backdoor analyzed.

CVE-2026-50746 UniFi OS CVSS 10 command injection, CVE-2026-50656 Defender RoguePlanet exploit, UAT-7810 LONGLEASH ORB malware, ColdFusion KEV deadline.

CVE-2026-43499 GhostLock grants instant root on Linux since 2011. CVE-2026-48282 ColdFusion CVSS 10 added to KEV. KDDI 12M credential breach confirmed.

CVE-2026-53359 KVM VM escape has public PoC after 16 years. Plus BeyondTrust CVSS 9.2 auth bypass and China-nexus ORB malware from Talos.