Seite wählen

29.07.2026

Arista patches maximum severity vulnerability that is already being exploited

CSO Online 29.07.2026 00:43
Arista has patched a VeloCloud Orchestrator (VCO) security hole that has been actively leveraged in the wild, one that the vendor says “may allow a remote attacker to access privileged internal functionality and impact the VCO host.”
The Arista security advisory added that the hole “may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.”

Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root

The Hacker News 28.07.2026 12:56
OpenWrt has shipped version 24.10.8 to close a critical DHCPv6 stack overflow and a wider set of remotely triggerable flaws in network services enabled by default.

The critical issue, tracked as CVE-2026-53921 and rated 9.8 on CVSS 3.1 in OpenWrt's GitHub advisory, lets an unauthenticated attacker able to reach the DHCPv6 server overwrite a stack buffer in odhcpd through a crafted DHCPv6

Certighost: Gefährlicher Exploit lässt Angreifer Windows-Domänen kapern

Golem 28.07.2026 11:17
Im Netz kursiert ein Exploit, mit dem sich Windows-Domänen kompromittieren lassen. Admins sollten ihre Systeme dringend absichern. (Sicherheitslücke, Microsoft)

Microsoft: Proof-of-Concept-Exploit für „Certighost“-AD-Lücke aufgetaucht

Heise Security 28.07.2026 11:00
Am Juli-Patchday hat Microsoft eine AD-Lücke geschlossen, die Rechteausweitung ermöglicht. Nun warnt das Unternehmen vor PoC-Exploit.

Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In

The Hacker News 28.07.2026 08:11
JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue that could result in arbitrary code execution.

The vulnerability, assigned CVE-2026-63077 (CVSS score: 9.8), affects all TeamCity On-Premises versions. It has been addressed in versions 2025.11.7 and 2026.1.3. TeamCity Cloud instances have already

Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw

The Hacker News 28.07.2026 04:43
A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild.

The vulnerability, tracked as CVE-2026-16812 (CVSS score: 10.0), is a case of operating system command injection that could pave the way for arbitrary code execution.

"VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue