Infosec News Nuggets — July 29, 2026
Brief
Arista patches VeloCloud Orchestrator zero-day exploited in attacks
Arista has shipped patches for a maximum-severity command injection flaw in on-premises VeloCloud Orchestrator deployments after confirming it is being actively exploited.
The bug allows unauthenticated attackers with only network access to the web interface to reach privileged internal functionality, potentially compromising the confidentiality, integrity, and availability of the orchestrator and the SD-WAN edge devices it manages.
Three attacker IP addresses have been identified, and the flaw has been added to the federal Known Exploited Vulnerabilities catalog with a three-day remediation deadline.
Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root
OpenWrt has released version 24. 10.
