Arista patches VeloCloud Orchestrator zero-day exploited in attacks
Arista has shipped patches for a maximum-severity command injection flaw in on-premises VeloCloud Orchestrator deployments after confirming it is being actively exploited. The bug allows unauthenticated attackers with only network access to the web interface to reach privileged internal functionality, potentially compromising the confidentiality, integrity, and availability of the orchestrator and the SD-WAN edge devices it manages. Three attacker IP addresses have been identified, and the flaw has been added to the federal Known Exploited Vulnerabilities catalog with a three-day remediation deadline.
Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root
OpenWrt has released version 24.10.8 to fix a critical stack overflow in its odhcpd DHCPv6 service that can be triggered by a single crafted, unauthenticated network request. Because odhcpd runs as root and many embedded routers lack stack canaries or ASLR, successful exploitation could hand an attacker full control of the device rather than just crashing it. The release also patches a separate set of pre-authentication weaknesses uncovered through an AI-assisted security audit, though related fixes for optional web-interface components remained under review as of publication.
Hackers Exploiting FastJson RCE 0-Day in the Wild to Attack US-based Organizations
Attackers are actively exploiting an unpatched deserialization flaw in FastJson 1.x, a widely used Java library for converting between Java objects and JSON, to gain remote code execution on Spring Boot applications packaged as executable JAR files. The bypass works without valid credentials, user interaction, or third-party gadget classes, letting a single malicious JSON payload trigger arbitrary command execution. Exploitation has concentrated on US financial, healthcare, retail, and business services organizations, with smaller campaigns spotted in Singapore and Canada; since the affected release line is no longer maintained, defenders are advised to enable the library’s safe mode immediately and plan a migration to FastJson 2.x.
Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522)
Researchers observed active exploitation of a critical unauthenticated remote code execution flaw in on-premises Microsoft SharePoint within hours of a proof-of-concept exploit going public, with attackers stealing IIS machine keys to maintain long-term access even after patching. Threat intelligence suggests exploitation may have actually begun days earlier, before the PoC surfaced. Because forged authentication tokens built from stolen keys let attackers impersonate legitimate users, organizations that already applied the underlying patch are being urged to also rotate credentials and hunt for intrusion artifacts rather than treating patching alone as sufficient remediation.
Clop exploits vulnerability in PTC Windchill and FlexPLM
A Clop-affiliated group is chaining a pre-authentication information leak with a remote code execution flaw in the login servlet of PTC’s Windchill and FlexPLM product lifecycle management software to deploy webshells and steal sensitive engineering and design data from manufacturing, automotive, aerospace, and retail companies. Researchers believe the underlying vulnerability was exploited as a zero-day starting in early June before being publicly disclosed and patched, and the group has since launched a mass email extortion campaign targeting hundreds of employees per victim organization, mirroring tactics used in last year’s Oracle E-Business Suite campaign.