← All briefings

Arista VeloCloud Orchestrator On-Prem · Fortinet FortiOS · vBulletin 5.x / 6.x

Date: 2026-07-28 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership


Executive Summary

Two new CISA KEV entries dominate today’s briefing: a Fortinet FortiOS information-disclosure flaw enabling patch-bypass via crafted HTTP requests (CVE-2025-68686, due 2026-08-10) and a maximum-severity OS command injection in Arista VeloCloud Orchestrator (CVE-2026-16812, due 2026-07-30 — three days). A public exploit for the vBulletin pre-auth RCE (CVE-2026-61511) was released today. JFrog Artifactory received a cluster of four high-severity fixes. A FastJson zero-day RCE is under active exploitation against US firms.


Critical Vulnerabilities

CVE-2026-16812 — Arista VeloCloud Orchestrator On-Prem

  • Severity: CVSS 10.0
  • EPSS: 0 (newly published; KEV-confirmed exploitation supersedes score)
  • Technical detail: OS command injection in the on-premises VeloCloud Orchestrator allows a remote, unauthenticated attacker to access privileged internal functionality and fully compromise the VCO host. Affected versions span 5.2.x < 5.2.3.14, 6.1.x < 6.1.3.4, 6.4.x < 6.4.2.4, and 7.0.x < 7.0.0.1. The orchestrator manages SD-WAN edge devices, so a successful compromise can cascade to all managed network edges.
  • Exploitation status: Actively exploited; added to CISA KEV 2026-07-27. Federal deadline: 2026-07-30.
  • Remediation: Upgrade to the respective fixed release immediately. If patching cannot be completed before 2026-07-30, isolate the VCO management interface from internet exposure and restrict access to trusted management networks only.

CVE-2025-68686 — Fortinet FortiOS

  • Severity: Not yet scored (CWE-200 information disclosure)
  • EPSS: Not yet scored; KEV-confirmed exploitation
  • Technical detail: An exposure of sensitive information vulnerability in FortiOS allows a remote, unauthenticated attacker to bypass the symbolic-link persistency patch applied in prior remediation cycles via crafted HTTP requests. Exploitation requires prior filesystem-level compromise through a separate vulnerability — this flaw enables persistence re-establishment after patching. Particularly dangerous in environments that patched earlier FortiOS symbolic-link issues but did not perform full forensic remediation.
  • Exploitation status: Actively exploited; added to CISA KEV 2026-07-27. Federal deadline: 2026-08-10.
  • Remediation: Apply the latest FortiOS patch. Critically, also conduct a full forensic review of the filesystem for residual symbolic links or backdoors — patching alone is insufficient if the device was previously compromised. Refer to Fortinet’s prior PSIRT guidance on post-exploit persistence indicators.

CVE-2026-61511 — vBulletin 5.x / 6.x

  • Severity: CVSS 9.3
  • EPSS: 0 (newly published; public exploit released)
  • Technical detail: An eval injection vulnerability in vB5_Template_Runtime::runMaths() within the template runtime allows unauthenticated remote code execution. No account, administrative access, or user interaction is required. Affects vBulletin 5.0.0–5.7.5 and 6.0.0–6.2.1. A public exploit was released by SSD Secure Disclosure on 2026-07-27, demonstrating how a crafted unauthenticated request reaches PHP’s eval() function directly.
  • Exploitation status: Public exploit available; exploitation in the wild expected imminently. BSI advisory WID-SEC-2026-2528 published.
  • Remediation: Upgrade to vBulletin 6.2.2 immediately. If patching is not immediately possible, restrict public access to the forum or place it behind authentication at the web server/WAF layer.

CVE-2026-63077 — JetBrains TeamCity

  • Severity: CVSS 9.8
  • EPSS: 0 (newly published)
  • Technical detail: Unauthenticated remote code execution via the agent polling protocol in JetBrains TeamCity before versions 2026.1.3 and 2025.11.7. The agent polling protocol is typically exposed to build agents and may be reachable from internal networks or, in misconfigured deployments, from the internet. TeamCity has a history of rapid exploitation following disclosure.
  • Exploitation status: No confirmed exploitation yet; given TeamCity’s exploitation history, treat as high-urgency.
  • Remediation: Upgrade to TeamCity 2026.1.3 or 2025.11.7 immediately. Restrict agent polling port exposure to known build agent IP ranges.

JFrog Artifactory — Multiple High-Severity Vulnerabilities (CVE-2026-65616, CVE-2026-66014, CVE-2026-65617, CVE-2026-42017)

  • Severity: CVSS 8.8 (all four)
  • EPSS: 0 (newly published)
  • Technical detail: JFrog published four vulnerabilities in Artifactory on 2026-07-27. CVE-2026-65616 allows non-admin users to obtain a signed administrator JWT token via incorrect refresh token signature validation. CVE-2026-66014 enables privilege escalation through an authentication handling weakness in internal request processing. CVE-2026-65617 is a deserialization weakness allowing a low-privileged user to impact CIA under specific repository conditions. CVE-2026-42017 exposes privileged authorization material to lower-privileged users via an event-handling weakness. Affected versions vary; fixed in 7.111.18, 7.117.25, 7.125.18, 7.133.27, 7.146.34, and 7.161.15 depending on the CVE.
  • Exploitation status: No confirmed exploitation.
  • Remediation: Apply the appropriate fixed Artifactory release for your version track. Audit access logs for anomalous token usage or privilege escalation indicators.

ONGOING:

  • CVE-2026-16723 (Fastjson 1.x): NEW STATUS — active zero-day exploitation against US firms confirmed (BleepingComputer 2026-07-27); migrate to Fastjson 2.x immediately, treat exposed instances as compromised.
  • CVE-2026-57989 / CVE-2026-57990 (Microsoft Edge): no exploitation confirmed; update to ≥150.0.4078.99.
  • Certighost (ADCS): working public PoC; audit certificate templates, monitor DCSync events.
  • CVE-2026-0257 (PAN-OS GlobalProtect): Qilin ransomware exploitation ongoing; patch immediately.
  • CVE-2026-6875 (ServiceNow AI Platform): exploitation continues; patch and restrict access.
  • CVE-2026-6516 (ManageEngine ADAudit Plus): unauthenticated RCE; upgrade to build 8606.
  • CVE-2026-16232 (Check Point SmartConsole): KEV deadline passed — treat unpatched as compromised.
  • CVE-2026-50522 (SharePoint): KEV deadline passed — conduct compromise assessment.

European Advisories

BSI published several new and updated advisories on 2026-07-27:

WID-SEC-2026-2528 (vBulletin): Covered in Critical Vulnerabilities — CVE-2026-61511.

WID-SEC-2026-2525 (Zabbix — UNPATCHED): BSI rates this critical. A remote, unauthenticated attacker can exploit a stored XSS vulnerability in Zabbix. Notably marked UNGEPATCHT — no vendor fix is currently available. Organizations should restrict Zabbix web interface access to trusted internal networks and enforce strict CSP headers as a temporary mitigation.

WID-SEC-2026-2526 (ffmpeg): Multiple high-severity flaws enabling memory corruption, arbitrary code execution, DoS, and information disclosure via crafted media files. Update ffmpeg to the latest available release; review any pipelines processing untrusted media.

WID-SEC-2026-2316 (Microsoft Windows — UPDATE): BSI updated its advisory for multiple Windows vulnerabilities. Apply current Patch Tuesday updates.

BSI also issued routine updates for: Linux Kernel (multiple advisories), GnuTLS, FreeRDP, Aqua Security Trivy, Unbound, ProFTPD, Shibboleth Service Provider, Apache Tomcat, and Golang Go — apply vendor patches per standard patch management cycles.


Active Threats and Campaigns

NEW — FastJson Zero-Day RCE (Active Exploitation): BleepingComputer reports active exploitation of an unpatched RCE vulnerability in the FastJson open-source Java library targeting US firms. No CVE has been assigned to this specific zero-day yet (distinct from the previously tracked CVE-2026-16723 in Fastjson 1.x — confirm which version track is affected in your environment). Exploitation requires no user interaction or elevated privileges. Organizations using FastJson in any version should treat exposed instances as potentially compromised and migrate to Fastjson 2.x or an alternative library immediately.

NEW — Operation BlueDash (Fake Teams Update / RMM Delivery): A phishing campaign uses Microsoft Teams-themed “secure document” lures to redirect victims through compromised web infrastructure to a counterfeit Microsoft Store page. The page delivers legitimate RMM tools (Level RMM and ScreenConnect) for persistent access. Hunt for unauthorized RMM tool installations and review browser proxy logs for counterfeit Microsoft Store domains.

NEW — TELESHIM Campaign (East Asia → Middle East Governments): Zscaler ThreatLabz identified an East Asia-linked threat actor deploying novel malware families TELESHIM, MIXEDKEY, and BINDCLOAK against Middle East government entities, using Telegram for C2. European organizations with Middle East government partnerships should review third-party access and monitor for Telegram-based C2 traffic.

ONGOING — Dysphoria IoT Botnet: Now confirmed at ~200,000 compromised devices globally; adopted blockchain-based C2 and infected-device relays post-JackSkid disruption. Patch internet-facing IoT devices; block known botnet infrastructure.

ONGOING — SourTrade Malvertising: No new developments; block malicious domains at DNS/proxy, monitor for Bun runtime abuse.


Security News and Context

  • MOVEit new vulnerabilities: Heise Security reports multiple new security flaws in MOVEit Transfer, including authentication issues. Organizations running MOVEit should apply the latest security update immediately given the product’s prior exploitation history.
  • ShinyHunters claims Ernst & Young breach: The group alleges credential theft via a supply-chain attack; BleepingComputer reports the claim is unverified. Organizations with EY vendor relationships should review shared access and credentials.
  • Coca-Cola/Fairlife ransomware: Confirmed data theft from a ransomware attack on Fairlife; no European operational impact reported.
  • vBulletin public exploit: Covered in Critical Vulnerabilities.

  1. Arista VeloCloud Orchestrator (CVE-2026-16812): Patch to fixed release before 2026-07-30 deadline; if not possible, immediately isolate VCO management interface from internet.
  2. Fortinet FortiOS (CVE-2025-68686): Apply latest FortiOS patch AND conduct full filesystem forensic review for residual symbolic links — patching alone is insufficient.
  3. vBulletin (CVE-2026-61511): Upgrade to 6.2.2 immediately; public exploit is live and unauthenticated exploitation is imminent.
  4. JetBrains TeamCity (CVE-2026-63077): Upgrade to 2026.1.3 / 2025.11.7; restrict agent polling port to known build agent IPs.
  5. JFrog Artifactory (CVE-2026-65616 et al.): Apply fixed release for your version track; audit access logs for anomalous token or privilege activity.
  6. Zabbix (unpatched XSS): Restrict Zabbix web interface to internal networks only; enforce CSP headers until a vendor patch is available.
  7. MOVEit Transfer: Apply latest security update; review authentication logs for anomalous access.
  8. FastJson zero-day: Migrate to Fastjson 2.x immediately; treat any internet-exposed FastJson 1.x instances as potentially compromised.
  9. Operation BlueDash: Hunt for unauthorized Level RMM / ScreenConnect installations; brief users on fake Microsoft Store lures.
  10. Continue remediation of previously reported items: Certighost (ADCS), PAN-OS (CVE-2026-0257), ServiceNow (CVE-2026-6875), ManageEngine (CVE-2026-6516), Check Point SmartConsole (CVE-2026-16232 — treat as compromised), SharePoint (CVE-2026-50522 — compromise assessment), Microsoft Edge (CVE-2026-57989/57990).