Tuesday, July 28, 2026
Daily digest
The dominant story today is the actively-exploited, maximum-severity Arista VeloCloud Orchestrator flaw (CVE-2026-16812) — CISA is already pushing agencies to patch, and it's a top priority for anyone running SD-WAN edge infrastructure.
Arista VeloCloud Orchestrator Command Injection Actively Exploited (CVE-2026-16812)
A maximum-severity (CVSS 10.0) OS command injection vulnerability in on-premises Arista VeloCloud Orchestrator is being actively exploited in the wild. CISA has flagged the bug and Arista has released patches; the flaw allows unauthenticated attackers to gain arbitrary code execution and potentially control managed Edge devices.
Why it matters: If VeloCloud is anywhere in your SD-WAN or branch connectivity stack, treat this as an emergency patch — active exploitation plus a perfect CVSS score means it will likely appear on CISA KEV and trigger BOD 22-01 remediation deadlines.
Critical TeamCity On-Premises Flaw Allows Unauthenticated Code Execution
JetBrains disclosed CVE-2026-63077 (CVSS 9.8), a critical vulnerability in all on-premises TeamCity versions that allows arbitrary code execution without authentication. Fixes are available in versions 2025.11.7 and 2026.1.3; TeamCity Cloud is already patched.
Why it matters: If TeamCity anchors any CI/CD pipeline feeding Ansible playbooks or container builds, an unauthenticated RCE here is a direct path to supply-chain compromise — patch before the next build cycle.
FastJson Zero-Day Exploited in Attacks on US Firms
Attackers are actively exploiting a remote code execution vulnerability in the widely-used FastJson open-source Java library, requiring no user interaction or elevated privileges. The campaign is specifically targeting US organizations.
Why it matters: FastJson is a common transitive dependency in Java-based enterprise apps; inventory any internal or vendor apps using it, since exploitation requires no auth or interaction.
Certighost PoC Exploit Enables Windows Domain Takeover via AD CS
A public proof-of-concept exploit dubbed "Certighost" targets a vulnerability in Windows Active Directory Certificate Services, allowing authenticated attackers to potentially compromise an entire Windows domain.
Why it matters: AD CS misconfigurations are common in gov-adjacent environments; with a public PoC now available, audit certificate templates and enrollment permissions in your Intune-managed AD before this gets weaponized broadly.
24,000+ Exposed Server BMCs Leak Password Hashes via 20-Year-Old Flaw
Researchers found more than 24,000 internet-exposed servers leaking authentication password hashes through their Baseboard Management Controller (BMC) interfaces, caused by a two-decade-old vulnerability. The issue affects out-of-band management systems across multiple hardware vendors.
Why it matters: Verify that IPMI/BMC interfaces on Nutanix nodes and other bare-metal hosts are not internet-facing and are on isolated management VLANs — this is a classic 800-171 network segmentation finding.
n8n Sandbox Escape Allows OS Command Execution on Automation Server
A high-severity expression-sandbox escape in the n8n workflow automation platform lets an authenticated workflow editor run OS commands as the n8n process. n8n patched the flaw, found while researchers probed a February fix for a related bypass, in versions 2.31.5 and 2.32.1.
Why it matters: If n8n is used alongside or instead of Ansible for orchestration, patch immediately — a sandbox escape in an automation platform can quickly become a lateral-movement foothold.
Microsoft Defender for Endpoint Update Breaks Protection on Some Linux Hosts
A recent Microsoft Defender for Endpoint update introduced two bugs on Linux: one disables the security service after a restart, another blocks installation on hardened RHEL systems. Microsoft has acknowledged the issues.
Why it matters: Check any RHEL-based servers (including Nutanix AHV-adjacent Linux workloads) running Defender for Endpoint for silent protection gaps — this directly undermines continuous monitoring controls required for CMMC L2.
'Confused Deputy' Flaws Persist Across Google Cloud and Microsoft Azure
Researchers describe an ongoing class of cloud vulnerabilities called "confused deputy" flaws that let attackers acquire administrative-level permissions and bypass cloud providers' access controls in both Google Cloud and Microsoft Azure. The issue stems from how services with high-privilege roles process requests on behalf of lower-privileged callers.
Why it matters: Review cross-service and cross-tenant trust relationships in your GCC High/Azure Government tenant — confused deputy patterns often hide in managed identities and service principals that auditors won't catch by default.
Senator Wyden Pushes CISA, OMB, NIST to Purge Outdated VPNs from Federal Agencies
Sen. Ron Wyden sent a letter urging CISA, OMB, and NIST to lead a coordinated federal effort to identify and remove obsolete VPN products across government agencies, citing them as a persistent attack vector.
Why it matters: If this gains traction, expect updated NIST guidance or SP 800-171 assessment criteria around remote access appliances — worth getting ahead of by inventorying VPN end-of-life status now.
AWS Shield Advanced Adopting AWS WAF Anti-DDoS Managed Rule Group
AWS announced that Shield Advanced is integrating the AWS WAF Anti-DDoS managed rule group, originally launched in June 2025, to better detect application-layer DDoS attacks that mimic legitimate traffic. AWS published guidance on configuration changes customers need to make to prepare.
Why it matters: GovCloud workloads behind Shield Advanced should review WAF rule group associations before the transition to avoid gaps in DDoS mitigation coverage.
Cloud Security Alliance Releases AWS Compliance Guide Mapping CCM to AWS Services
AWS Security Assurance Services published a Cloud Security Alliance (CSA) Compliance Guide mapping the 17 control domains and 207 control objectives of the Cloud Controls Matrix v4.1 to specific AWS services and implementation practices.
Why it matters: Useful reference for mapping AWS GovCloud service configurations to CCM/NIST 800-171 control families during SSP documentation or C3PAO assessment prep.
Talos Q2 2026 IR Trends: Phishing and Weaponized RMM Tools Drive Attack Chains
Cisco Talos' Q2 2026 incident response report finds a significant surge in phishing as an initial access vector, alongside growing abuse of legitimate remote monitoring and management (RMM) tools by attackers for persistence and lateral movement.
Why it matters: Reinforces the need to tightly scope which RMM tools are allowlisted in Intune and to monitor for unauthorized installs, since attackers increasingly favor legitimate tools over custom malware to evade detection.