View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Arista VeloCloud Orchestrator On-Prem Command Injection Exploited

๐Ÿšจ ACTIVE EXPLOITATION

  • Arista VeloCloud Orchestrator On-Prem OS Command Injection (CVE-2026-16812) Exploited CVE-2026-16812
    Hackers are actively exploiting a critical command injection vulnerability in Arista VeloCloud Orchestrator on-prem servers.
    • Applies to Arista VeloCloud Orchestrator on-premises servers
    • Vulnerability is a CVSS 10.0 remote code execution via OS command injection
    • Exploitation allows attackers total control of affected assets
    • Attack observed in the wild, prompting CISA to add CVE-2026-16812 to its Known Exploited Vulnerabilities Catalog
    • Federal agencies mandated to prioritize remediation under BOD 26-04
      ๐Ÿ“Ž Coverage: arista.com ยท ๐Ÿ“„ Original: cisa.gov ยท ๐Ÿ‘ via @campuscodi@mastodon.social

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • AI-Assisted Research Finds Linux Kernel Zero-Day LPE in net/sched Subsystem CVE-2026-0770
    Researchers discovered a Linux kernel zero-day enabling local root privilege escalation.

    • Applies to Linux kernel net/sched packet scheduling subsystem
    • Vulnerability is a use-after-free in tcf_idr_check_alloc() causing race condition
    • Exploited via RTM_NEWTFILTER and RTM_DELTFILTER netlink routes in unprivileged user namespaces
    • Exploit uses KASLR leak, heap reclamation, and ROP to gain root privileges
    • Tested successfully on CentOS Stream 9 desktop with exploit under 10 seconds
      ๐Ÿ“Ž Coverage: cybersecuritynews.com ยท ๐Ÿ‘ via Cyber Security News
  • Over 24,000 exposed server BMCs leak password hashes via 20-year-old flaw
    More than 24,000 internet-exposed server BMCs leak password hashes due to an old vulnerability.

    • Applies to over 24,000 internet-exposed servers with Baseboard Management Controllers (BMCs)
    • Vulnerability is a 20-year-old IPMI 2.0 authentication flaw (CVE-2013-4786) allowing password hash leaks
    • Attackers can request authentication responses to crack passwords offline using GPU rigs
    • Many exposed BMCs use weak or default passwords, including Supermicro systems with factory-set credentials
    • Exploitation could allow attackers to control physical servers and pivot across management interfaces
      ๐Ÿ“Ž Coverage: bleepingcomputer.com ยท ๐Ÿ‘ via BleepingComputer
  • Out-of-bounds write in ImsService enables remote code execution in Android 14-16 CVE-2026-21047
    An out-of-bounds write vulnerability in ImsService allows remote code execution on affected Android versions.

    • Affects Android versions 14, 15, and 16 prior to SMR Jul-2026 Release 1
    • Vulnerability is an out-of-bounds write in the ImsService component
    • Allows remote attackers to potentially execute arbitrary code
    • No user interaction or privileges required for exploitation
      ๐Ÿ“Ž Coverage: cve.threatint.com ยท ๐Ÿ“„ Original: cve.threatint.com ยท ๐Ÿ‘ via CVE ThreatInt
  • Critical Unauthenticated RCE in Joomla Balbooa Forms Versions Below 2.4.3 CVE-2026-65880
    An unauthenticated remote code execution vulnerability affects Joomla Balbooa Forms below version 2.4.3.

    • Applies to Joomla Balbooa Forms extension versions 1.0.0 to 2.4.2.1
    • Vulnerability allows unauthenticated remote code execution via insecure form processing
    • Exploited through forms including the signature field type
    • CVSS 10.0 with high impact on confidentiality, integrity, and availability
    • Identified as CWE-94: Improper Control of Generation of Code (Code Injection)
      ๐Ÿ“Ž Coverage: cve.threatint.com ยท ๐Ÿ‘ via CVE ThreatInt
  • CastleLoader Campaign Uses Fake Crypto Wallet Screens to Steal Recovery Phrases and Browser Sessions
    Hackers use fake crypto wallet screens and browser extensions to steal recovery phrases and sessions.

    • Targets Windows users managing cryptocurrency wallets including Ledger, Trezor, and Exodus
    • Uses Rust-based wallet spoofer showing fake recovery phrase prompts to steal secrets
    • Delivered via fake software installers, ClickFix-style prompts, and Node.js injectors
    • Includes malicious Golang browser extensions posing as ad blockers to hijack sessions
    • Employs social engineering to trick victims into running harmful PowerShell commands
      ๐Ÿ“Ž Coverage: cybersecuritynews.com

โš ๏ธ TALOS Q2 2026 IR REPORT

  • Talos Q2 2026 IR report: Phishing surges, weaponized remote tools aid ransomware
    Cisco Talos reports increased phishing and use of legitimate remote tools in attacks.
    • Phishing caused initial access in over 50% of cases, up from ~33% last quarter
    • Attackers use QR code-embedded PDFs and trusted cloud platforms to evade email defenses
    • Authentication abuse rose to 65% of cases, with MFA bypass via AitM proxies, token theft, and MFA fatigue
    • Ransomware incidents over 20%, including Sinobi using trojanized MeshAgent and Zoho Assist for stealthy access
    • Persistent QR phishing campaign targets Australian orgs via compromised Microsoft 365 accounts and internal contacts
    • ARToken phishing-as-a-service platform enables MFA bypass and post-compromise token management
    • Sinobi ransomware operators weaponize MeshAgent as covert backdoor, deploy ransomware via GPO scripts
      ๐Ÿ“Ž Coverage: blog.talosintelligence.com ยท ๐Ÿ“„ Original: blog.talosintelligence.com ยท ๐Ÿ‘ via Cisco Talos

๐Ÿ”“ CVEs & KEV

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check