decrypted · 28 july 2026 · ransomware and cybercrime · vulnerabilities and patching · uk policy and law
An SD-WAN console with no way to hide, and the flaw attackers found first
Arista pushed emergency patches this week for VeloCloud Orchestrator, the console that runs SD-WAN networks for enterprises, after confirming a maximum severity flaw was already being used against customers. The vulnerability itself, CVE-2026-16812, is an unauthenticated command injection: send the right web request and you run commands as the orchestrator, no login required. What makes it worth five minutes is the sentence in Arista's own advisory. The console, the company said, is exposed by default with no configuration option to prevent that exposure. There was never a switch to turn this off.
What happened
Arista published the fix on 27 July, the same day CISA added CVE-2026-16812 to its Known Exploited Vulnerabilities catalogue, with federal agencies given until 30 July to patch. The flaw scores a full 10.0 on both CVSS 3.1 and 4.0: no authentication needed, low attack complexity, complete compromise of confidentiality, integrity and availability. Arista says the bug was discovered externally, through evidence of active exploitation, rather than by its own testing, and it has published three IP addresses already linked to attacks. On-premises VCO deployments before versions 5.2.3.14, 6.1.3.4, 6.4.2.4 and 7.0.0.1 are affected; Arista's own hosted and dedicated instances were patched before the advisory went out, which tells you which side of this problem the company wanted to be on.
The design lesson
An orchestrator console exists to manage everything downstream of it: every edge device, every site, every tunnel on an SD-WAN. That makes it an obvious target and an equally obvious candidate for network segmentation as a default, not an afterthought. Arista's admission that there was no setting to restrict exposure is the tell here. A management plane for critical infrastructure should ship bound to an internal network or a VPN, with internet exposure something an administrator has to deliberately choose, not something the product forces on them regardless. Any UK organisation running an SD-WAN, firewall or VPN orchestrator has a question worth putting to its vendor this week: can the admin interface be taken off the public internet, and was that even possible before today.
Also this week
A ransomware claim against the Department for Education. The extortion group ExfilSquad listed the Department for Education on its leak site on 26 July, claiming around 607,000 records taken from two portals used by parents and staff, mostly names, email addresses, phone numbers and job titles. This is, for now, a claim on a criminal leak site rather than a confirmed breach. No independent verification of the group's assertions has been published, and the department has not confirmed an incident. Worth watching, not yet a fact.
The AsyncAPI npm compromise, still being unpacked. Microsoft's investigation, published in mid-July, traced a supply chain attack on the widely used AsyncAPI packages to a misconfigured GitHub Actions workflow: a pull_request_target trigger that let attacker-controlled pull request code run with a privileged bot token. Five malicious package versions, published through packages that see over three million downloads a week, delivered a credential-stealing payload across Windows, Linux and macOS before anyone noticed. The lesson for any UK team publishing to npm is the same one CI pipelines keep failing to learn: a workflow trigger that runs untrusted code with trusted credentials is a design choice, not bad luck.
Ofcom's Online Safety deadlines land this week. Ofcom has designated eleven platforms as Category 1 services under the Online Safety Act, and firms served with risk assessment notices earlier this year must submit their records by 31 July. Alongside it, the Department for Science, Innovation and Technology set out plans for under-18 protections, including overnight social media restrictions and mandatory breaks for children using AI chatbots. None of it changes the underlying argument about age assurance built to guess rather than verify, but the compliance clock most UK platforms have been watching from a distance now has a hard date attached.
Sources
- Arista Security Advisory 0144 (CVE-2026-16812)
- Arista patches VeloCloud Orchestrator zero-day exploited in attacks - BleepingComputer
- UK Department for Education Listed by ExfilSquad Ransomware Group - GalaxyWarden
- Ransomware Group ExfilSquad Hits: UK Department for Education - HookPhish
- Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery - Microsoft Security Blog
- UK online safety update: Ofcom's Category 1 proposals and DSIT's latest response to "Growing Up in an Online World" - Inside Global Tech
If you're reviewing what your own network vendors expose by default, get in touch.
More like this
- The Craneware breach, and the 2,000 hospitals waiting on Edinburgh 26 july 2026
- The Windchill flaw PTC patched in June, and the extortion campaign that followed 25 july 2026
- Routers left on factory settings, and the sanctions that came the same day 14 july 2026
Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.