decrypted · 28 july 2026 · ransomware and cybercrime · vulnerabilities and patching · uk policy and law

An SD-WAN console with no way to hide, and the flaw attackers found first

Arista pushed emergency patches this week for VeloCloud Orchestrator, the console that runs SD-WAN networks for enterprises, after confirming a maximum severity flaw was already being used against customers. The vulnerability itself, CVE-2026-16812, is an unauthenticated command injection: send the right web request and you run commands as the orchestrator, no login required. What makes it worth five minutes is the sentence in Arista's own advisory. The console, the company said, is exposed by default with no configuration option to prevent that exposure. There was never a switch to turn this off.

What happened

Arista published the fix on 27 July, the same day CISA added CVE-2026-16812 to its Known Exploited Vulnerabilities catalogue, with federal agencies given until 30 July to patch. The flaw scores a full 10.0 on both CVSS 3.1 and 4.0: no authentication needed, low attack complexity, complete compromise of confidentiality, integrity and availability. Arista says the bug was discovered externally, through evidence of active exploitation, rather than by its own testing, and it has published three IP addresses already linked to attacks. On-premises VCO deployments before versions 5.2.3.14, 6.1.3.4, 6.4.2.4 and 7.0.0.1 are affected; Arista's own hosted and dedicated instances were patched before the advisory went out, which tells you which side of this problem the company wanted to be on.

The design lesson

An orchestrator console exists to manage everything downstream of it: every edge device, every site, every tunnel on an SD-WAN. That makes it an obvious target and an equally obvious candidate for network segmentation as a default, not an afterthought. Arista's admission that there was no setting to restrict exposure is the tell here. A management plane for critical infrastructure should ship bound to an internal network or a VPN, with internet exposure something an administrator has to deliberately choose, not something the product forces on them regardless. Any UK organisation running an SD-WAN, firewall or VPN orchestrator has a question worth putting to its vendor this week: can the admin interface be taken off the public internet, and was that even possible before today.

Also this week

A ransomware claim against the Department for Education. The extortion group ExfilSquad listed the Department for Education on its leak site on 26 July, claiming around 607,000 records taken from two portals used by parents and staff, mostly names, email addresses, phone numbers and job titles. This is, for now, a claim on a criminal leak site rather than a confirmed breach. No independent verification of the group's assertions has been published, and the department has not confirmed an incident. Worth watching, not yet a fact.

The AsyncAPI npm compromise, still being unpacked. Microsoft's investigation, published in mid-July, traced a supply chain attack on the widely used AsyncAPI packages to a misconfigured GitHub Actions workflow: a pull_request_target trigger that let attacker-controlled pull request code run with a privileged bot token. Five malicious package versions, published through packages that see over three million downloads a week, delivered a credential-stealing payload across Windows, Linux and macOS before anyone noticed. The lesson for any UK team publishing to npm is the same one CI pipelines keep failing to learn: a workflow trigger that runs untrusted code with trusted credentials is a design choice, not bad luck.

Ofcom's Online Safety deadlines land this week. Ofcom has designated eleven platforms as Category 1 services under the Online Safety Act, and firms served with risk assessment notices earlier this year must submit their records by 31 July. Alongside it, the Department for Science, Innovation and Technology set out plans for under-18 protections, including overnight social media restrictions and mandatory breaks for children using AI chatbots. None of it changes the underlying argument about age assurance built to guess rather than verify, but the compliance clock most UK platforms have been watching from a distance now has a hard date attached.

Sources

If you're reviewing what your own network vendors expose by default, get in touch.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.