Announcements

Arista VeloCloud Orchestrator: Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability

  • 30th July 2026
A security flaw has been identified in Arista VeloCloud Orchestrator On-Prem, a platform used to manage network infrastructure. The issue is an OS command injection vulnerability, which allows a remote attacker to run unauthorized, high-privilege commands on the system that hosts this software.If successfully exploited, this could let bad actors ...
Continue reading

Fortinet FortiOS: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

  • 30th July 2026
A security vulnerability has been identified in Fortinet FortiOS, a widely used network security operating system. This flaw creates a risk of sensitive, private information stored on the device being exposed to unauthorized actors.The issue can be exploited by a remote unauthenticated attacker, but only if the attacker has already compromised the ...
Continue reading

Cisco Secure Firewall Management Center (FMC): Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability

  • 30th July 2026
A security vulnerability has been identified in Cisco Secure Firewall Management Center (FMC), a tool used to manage network firewall security systems. The flaw exists because the software uses a hard-coded password: a fixed, pre-set password built directly into the tool rather than being unique to each individual user account.This issue could ...
Continue reading

MA-1471.072026: MyCERT Advisory - Microsoft SharePoint Hardening After New Exploitations

  • 30th July 2026
On 20 July 2026, cybersecurity advisory group MyCERT released a notice focused on securing Microsoft SharePoint, a common tool used by businesses for document storage, team collaboration, and internal site management. The notice was issued after new methods for exploiting unsecured SharePoint installations were identified. These new exploitation ...
Continue reading