#activeexploit

11 posts · Last used 13d

Arista Networks Patches Critical VeloCloud Orchestrator Zero-Day Exploited in the Wild

Arista Networks disclosed a critical CVSS 10.0 vulnerability (CVE-2026-93952) in VeloCloud Orchestrator On-Prem that is being actively exploited to gain unauthenticated remote access to orchestrator hosts and managed edge devices.

If you run VeloCloud Orchestrator On-Prem, this is urgent. Make sure its web interface is not reachable from the internet and is accessible only from trusted admin networks, then update right away to a fixed version (5.2.3.16, 6.4.2.8 or later). Attackers are already using this flaw to take full control without any password. After patching, look for the hidden file /usr/local/sbin/.vcnode.js or the x-vc-opt header in your web logs, and if you find either, treat the orchestrator and every connected Edge device as compromised. #cybersecurity #infosec #attack #activeexploit https://beyondmachines.net/event_details/arista-networks-patches-critical-velocloud-orchestrator-zero-day-exploited-in-the-wild-4-k-v-7-w/gD2P6Ple2L

0
0
0
0

WSO2 Warns of Active Exploitation Targeting Critical Authentication Bypass

WSO2 is warning of active exploitation of a critical authentication bypass vulnerability (CVE-2026-5430) that allows attackers to take over administrative accounts and steal sensitive API credentials. The flaw affects multiple middleware products and has been targeted in the wild since mid-September 2026.

If you run WSO2 API Manager, API Control Plane, Traffic Manager, or Universal Gateway, check for affected versions and patch immediately to the latest update level from WSO2. If you are using open source version apply the public GitHub fix. Attackers are already using forged tokens to gain full admin access. After patching, assume your secrets were exposed and rotate all API keys, backend credentials, consumer keys, and application secrets, and check your logs for suspicious access since September 13, 2026. #cybersecurity #infosec #attack #activeexploit https://beyondmachines.net/event_details/wso2-warns-of-active-exploitation-targeting-critical-authentication-bypass-6-5-6-k-k/gD2P6Ple2L

0
0
0
0

Metabase Patches Critical Zero-Day SQL Injection Exploited in the Wild

Metabase patched a critical zero-day SQL injection vulnerability (GHSA-vwf4-m7j8-wcjf, CVSS 10.0) that is actively exploited to gain administrator access and steal database credentials.

If you run self-hosted Metabase (version 1.58 or newer), this is urgent. Your Metabase is under attack. Update immediately to the patched release for your branch (0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, or 0.63.5). if you can't patch right now, block all traffic to the /api/session/reset_password endpoint as a stopgap. After patching, check your application and ingress logs for a failed password-reset POST followed straight away by a successful /api/user/current request. Tf you see it, treat the instance as breached: clear the core_session table to log everyone out, rotate all connected database passwords, and check your admin accounts for anything you didn't create. #cybersecurity #infosec #attack #activeexploit https://beyondmachines.net/event_details/metabase-patches-critical-zero-day-sql-injection-exploited-in-the-wild-g-o-s-u-u/gD2P6Ple2L

0
0
0
0

N-able Patches Critical N-central Authentication Bypass Exploited in the Wild

N-able issued an emergency hotfix for N-central after attackers bypassed previous patches to gain administrative control over MSP servers. The flaw allows remote actors to hijack managed endpoints and establish persistent access via Cloudflare tunnels.

If you are using N-able N-central, this is urgent. Upgrade immediately to version 2026.3.1.7. Attackers are already exploiting the product to take over admin accounts on both on-premises and cloud-hosted servers. After patching, run N-able's provided scan templates on your Windows endpoints to check for signs of compromise (especially unexpected Cloudflare tunnel services), turn on multi-factor authentication, and review all user accounts and policy changes for anything you didn't make yourself. #cybersecurity #infosec #attack #activeexploit https://beyondmachines.net/event_details/n-able-patches-critical-n-central-authentication-bypass-exploited-in-the-wild-7-r-o-r-u/gD2P6Ple2L

0
0
0
0

Arista Patches Critical VeloCloud Orchestrator Zero-Day Under Active Attack

Arista Networks released an emergency advisory for a CVSS 10.0 OS command injection vulnerability in VeloCloud Orchestrator On-Prem that is currently being exploited in the wild. The flaw allows unauthenticated attackers to gain full control over the orchestrator and all managed SD-WAN edge devices.

Make sure all VeloCloud Orchestrator On-Prem devices are isolated from the internet and accessible only from trusted administrative networks. Then immediately upgrade to a fixed release (5.2.3.14, 6.1.3.4, 6.4.2.4, or 7.0.0.1) and block the known malicious IPs (8.19.75.217, 206.72.242.124, 206.72.242.162) at your firewall. After patching rotate all credentials and certificates so attackers can't reuse any potentially stolen data. #cybersecurity #infosec #attack #activeexploit https://beyondmachines.net/event_details/arista-patches-critical-velocloud-orchestrator-zero-day-under-active-attack-x-b-e-7-y/gD2P6Ple2L

0
0
0
0

CISA Warns of Active Exploitation in Fortinet FortiOS SSL-VPN Patch Bypass

CISA reports active explotation of CVE-2025-68686, a flaw in Fortinet FortiOS that allows attackers to bypass security patches and maintain persistent access on compromised devices.

If you use Fortinet devices, make sure they are isolated from the internet and accessible only from trusted networks. Then update FortiOS ASAP to version 7.6.2, 7.4.7, or later. This flaw is combined with others, so make sure all your Fortinet devices are up-to-date. And check your devices for indicators of compromise, this flaw allowed hackers to maintain access over patch cycles. #cybersecurity #infosec #attack #activeexploit https://beyondmachines.net/event_details/cisa-warns-of-active-exploitation-in-fortinet-fortios-ssl-vpn-patch-bypass-h-6-5-r-8/gD2P6Ple2L

0
0
0
0

Microsoft SharePoint On-Premises Servers Targeted by Critical Deserialization Exploit

Microsoft SharePoint on-premises servers are under active attack following the release of exploit code for CVE-2026-50522. Attackers are stealing machine keys to maintain persistent access.

If you run on-premises SharePoint, apply Microsoft's July 14 patch immediately to fix CVE-2026-50522. Note that patching alone is not enough, because attackers steal the server's machine keys and keep access afterwards. Rotate all machine keys and related credentials on any exposed server, and check your logs for signs someone already extracted them. #cybersecurity #infosec #attack #activeexploit https://beyondmachines.net/event_details/microsoft-sharepoint-on-premises-servers-targeted-by-critical-deserialization-exploit-y-l-4-3-b/gD2P6Ple2L

2
0
0
0

Critical ServiceNow AI Platform Flaw Exploited in Remote Code Execution Attacks

ServiceNow AI Platform is facing active exploitation of a critical sandbox escape vulnerability (CVE-2026-6875) that allows unauthenticated attackers to execute remote code.

If you self-host ServiceNow, apply the July 13th security patches ASAP. This being actively exploited and lets attackers take over your instance without login. After patching, check your logs for suspicious activity around the /assessment_thanks.do endpoint and review the Guarded Scripts list for any custom code that needs updating. #cybersecurity #infosec #attack #activeexploit https://beyondmachines.net/event_details/critical-servicenow-ai-platform-flaw-exploited-in-remote-code-execution-attacks-0-w-8-n-6/gD2P6Ple2L

0
0
0
0

CISA Issues Urgent Warning on SharePoint Server Exploitation

CISA warns of active exploitation of three SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164) used by threat actors to deploy malware and steal IIS machine keys. The agency also reports two additional critical flaws (CVE-2026-55040 and CVE-2026-58644) that pose a high risk for remote code execution and authentication bypass.

If you run on-premise SharePoint Server (2016, 2019, or Subscription Edition), apply the latest Microsoft security updates immediately. Three of these flaws are being actively exploited to deploy ransomware. Then check your servers for signs of breach before rotating your IIS machine keys, and block direct internet access to SharePoint (especially the Central Administration interface) by placing it behind a reverse proxy. #cybersecurity #infosec #attack #activeexploit https://beyondmachines.net/event_details/cisa-issues-urgent-warning-on-sharepoint-server-exploitation-o-9-u-8-x/gD2P6Ple2L

0
0
0
0

Critical RCE Vulnerabilities Exploited in Joomla Page Builder Extensions

CISA has warned of active exploitation of two critical RCE vulnerabilities in Joomla's SP Page Builder and Page Builder CK extensions. Attackers are using these flaws to upload web shells and create rogue Super Administrator accounts to maintain persistent access.

If you run Joomla with SP Page Builder or Page Builder CK, update SP Page Builder to 6.6.2 and Page Builder CK to 3.6.0 immediately. Both have critical flaws under active attack. Then check your user list for any accounts using the @secure.local email domain, delete any you find, scan the /images/ and /media/ folders for suspicious PHP files, and if anything looks compromised, change all database passwords and secret keys. #cybersecurity #infosec #attack #activeexploit https://beyondmachines.net/event_details/critical-rce-vulnerabilities-exploited-in-joomla-page-builder-extensions-v-v-q-9-p/gD2P6Ple2L

0
0
0
0

Langflow AI Framework Targeted by Critical IDOR and RCE Exploits

CISA and Sysdig researchers report active exploitation of two critical Langflow vulnerabilities, including a 9.9-rated IDOR and a 9.3-rated RCE, used to steal AI credentials and deploy malware.

If you are using Langflow, this is important and urgent. Make sure all Langflow instances are isolated from the internet and accessible only from trusted networks, then immediately update to Langflow version 1.9.1 or later to patch these actively exploited flaws. Check your system logs for connections to the malicious IP 45.207.216.55 or the /tmp/lang_pwn marker. If you find any indicators of compromise, rotate any API keys or credentials that were stored in your Langflow flows. #cybersecurity #infosec #attack #activeexploit https://beyondmachines.net/event_details/langflow-ai-framework-targeted-by-critical-idor-and-rce-exploits-i-0-s-2-w/gD2P6Ple2L

0
0
0
0
Gitea Docker Images Vulnerable to Critical Authentication Bypass, Already Attacked Gitea patched a critical authentication bypass vulnerability (CVE-2026-20896) in its Docker images that allows attackers to impersonate any user with a single HTTP header. The flaw is being exploited in the wild. **If you self-host Gitea, first make sure it's isolated from the internet and reachable only from trusted networks, then update to version 1.26.3 or later ASAP. If you can't update immediately, edit your app.ini to change REVERSE_PROXY_TRUSTED_PROXIES from * to your actual reverse proxy's specific IP address, and rotate all credentials and secrets stored in your repositories.** #cybersecurity #infosec #attack #activeexploit https://beyondmachines.net/event_details/gitea-docker-images-vulnerable-to-critical-authentication-bypass-already-attacked-c-9-8-p-p/gD2P6Ple2L
0
0
0
0

Attackers Exploit Critical Takeover Flaw in Oracle E-Business Suite

Researchers report actively exploit of a critical vulnerability (CVE-2026-46817) in Oracle E-Business Suite's financial module.

If you run Oracle E-Business Suite (versions 12.2.3 through 12.2.15), make sure your EBS instances are isolated from the public internet and reachable only from trusted networks via a VPN or secure gateway. Then apply the May 2026 Critical Security Patch Update ASAP. #cybersecurity #infosec #attack #activeexploit https://beyondmachines.net/event_details/attackers-exploit-critical-takeover-flaw-in-oracle-e-business-suite-v-f-z-k-l/gD2P6Ple2L

1
0
0
0
You've seen all posts