If you just remember one thing from this briefing…
This week's confirmed exploits were not against edge boxes — they were against the consoles that manage them.
CISA confirmed active exploitation of a maximum-severity flaw in Arista's VeloCloud SD-WAN orchestrator and a
hardcoded credential in Cisco's firewall management platform, both within three days of each other. Compromise
of either gives an attacker the platform that controls every site or device beneath it, not just one appliance.
Ask your infrastructure team this week: which of our management planes — SD-WAN, firewall, virtualisation,
identity — are reachable from anywhere they should not be, and when were they last checked, not patched.
Priority27 Jul
Edge and orchestration products added to the exploited-vulnerability catalogue
CISA added Fortinet FortiOS (CVE-2025-68686, an SSL-VPN symlink-persistence patch bypass) and Arista VeloCloud
Orchestrator (CVE-2026-16812, unauthenticated OS command injection, CVSS 10.0) to the KEV catalogue. The
VeloCloud flaw affects on-premises orchestrators; compromise propagates to every SD-WAN edge they manage.
So what: if any site connects over SD-WAN via an on-premises VeloCloud Orchestrator,
patch to 5.2.3.14, 6.1.3.4 or 6.4.2.4 immediately. Check FortiOS for symlink-persistence indicators
regardless of prior patch history.
Priority29 Jul
Hardcoded credential in Cisco Secure Firewall Management Center exploited
Cisco confirmed active exploitation of CVE-2026-20316: a hardcoded low-privileged account in the Secure
FMC web interface (CVSS 8.9), chainable with other FMC flaws to escalate privileges. CISA set a federal
remediation deadline of 1 August.
So what: FMC manages a firewall estate, not one device. Treat this as an
assume-compromise check, not a routine patch — the static account exists until the fixed release is
installed.
Watch27–30 Jul
Ransomware groups continue naming aerospace and aviation-adjacent suppliers
CRPxO, active only since March 2026, listed ten new US victims on 27 July including MRO Aerospace (military
aircraft component overhaul) and Qube Aviation Catering, claiming 87.3GB from the former. Separately, the
Kyber group claimed a breach of L3Harris on 30 July; L3Harris had not confirmed it at the time of writing.
So what: CRPxO is newly active and unverified — treat its claims as unconfirmed. Check
all three names against your supplier and integrator register regardless; an unconfirmed claim against a
real supplier still tells you where to look.
Watch29 Jul
VMware vCenter authentication bypass disclosed with no workaround
Broadcom's VMSA-2026-0006 discloses two critical vCenter flaws — CVE-2026-59309 and CVE-2026-59310, both CVSS
9.8 — allowing an unauthenticated attacker to bypass authentication and execute code. No exploitation
observed as of publication, and no workaround exists.
So what: vCenter and ESX commonly host virtualised OT and passenger-processing systems.
Patch on the vendor's timeline, not the next change window — detection cannot substitute for the update.