:

ARISTA PATCHES CRITICAL VELOCLOUD ZERO-DAY

SECURITY DESK1 MIN READ
MON, JUL 27, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Arista has released a patch for a maximum-severity command injection vulnerability in VeloCloud Orchestrator that is currently being exploited in active attacks.

The flaw affects on-premises VeloCloud Orchestrator deployments. Command injection vulnerabilities allow attackers to execute arbitrary commands on affected systems, potentially granting full control of the network infrastructure. VeloCloud Orchestrator is used to manage SD-WAN deployments across enterprise networks. The vulnerability's active exploitation indicates attackers are actively targeting organizations using on-premises versions of the platform. Arista has not disclosed specific technical details about the vulnerability or attack methods in early disclosures. Organizations running VeloCloud Orchestrator should prioritize applying the patch to affected systems. This marks another critical vulnerability in widely-deployed networking infrastructure, following similar high-severity issues in other SD-WAN and network management platforms.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Simply deleting files from old USB drives before disposal provides minimal data protection. Experts warn that deleted data can be recovered with basic tools, making proper wiping essential.

2H AGOIndustry Desk

CISA has confirmed that ransomware groups are actively exploiting two recently patched vulnerabilities in SonicWall SMA1000 devices, including a critical server-side request forgery flaw.

4H AGOSecurity Desk

A vulnerability in marketing automation platform Klaviyo allowed dozens of advertisers to access customer passwords. The bug has since been patched.

4H AGOIndustry Desk

A security researcher purchased the domain noreply.net and began receiving confidential company data sent by automated systems. The incident reveals how businesses misuse no-reply email addresses, treating them as digital trash cans without understanding the security risks.

4H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.