decrypted · 29 july 2026 · vulnerabilities and patching · supply chain · digital sovereignty
The SD-WAN orchestrator that needed no login, and the one before it
Arista disclosed on 28 July that VeloCloud Orchestrator, the console that runs the SD-WAN for thousands of branch networks, had a maximum severity flaw that needed no password at all to reach: CVE-2026-16812, CVSS 10.0, already under active exploitation before most customers had patched. It is the second unauthenticated takeover of a network orchestration console in as many weeks, and the pattern matters more than either bug alone.
The console that answered without asking who you were
VeloCloud Orchestrator is the single pane of glass operators use to configure and monitor every SD-WAN edge device on a network, from head office routing policy down to the till system's link at a branch. CVE-2026-16812 is an operating system command injection: Arista's advisory said the flaw may allow a remote attacker to access privileged internal functionality that was intended only for internal use, and no VCO tenant or operator credentials were needed to reach it. Anyone who could route a request to the web interface could run commands on the orchestrator itself, and from there potentially reach every edge device it manages.
Think of a building where the caretaker's override panel, the one that unlocks every door on every floor, sits in the public lobby with no keyhole fitted. It works exactly as intended for the caretaker, and exactly as well for anyone who wanders past. Arista has patched on-premises versions; hosted and dedicated deployments were already fixed before the advisory went out. CISA has given US federal agencies until 30 July, tomorrow, to update. Three exploiting IP addresses are already public.
A pattern, not an incident
This is the second time in a fortnight that a network orchestration console with no authentication requirement has turned up under active exploitation. Individually these are vendor bugs. Together they say something about how this class of software gets built: an orchestrator is valuable precisely because it has privileged reach into everything downstream, which makes it the highest value target on the network, yet it keeps shipping with management interfaces that are internet facing by default and treat reachable as equivalent to authorised.
For UK organisations the lesson is not simply patch faster, though that helps. It is to treat any orchestrator, controller or management plane console as a system that should never be reachable from the open internet, regardless of what the vendor's default configuration allows. Put it behind a VPN or an allowlist, assume the vendor's own authentication will eventually fail, and audit which of your suppliers' consoles are currently sitting in the equivalent of that unlocked lobby.
Also this week
Palo Alto Networks patched a GlobalProtect authentication bypass, CVE-2026-0257, back in the spring, but Arctic Wolf reported this month that the Qilin ransomware crew has been using it as a reliable way in, riding it from VPN compromise straight through to domain-wide encryption in intrusions running through June, with some escalating to full double extortion. A patch's age tells you nothing about whether exploiting the gap it closes is still profitable; if a fix exists and a network hasn't applied it, someone is very likely trying it.
HM Treasury's designation of AWS, Google Cloud, Microsoft and Oracle as Critical Third Parties took effect on 13 July, putting the four under direct oversight from the Bank of England, the PRA and the FCA. The trigger was blunt: well over half of UK financial firms depend on the same handful of providers, so a single outage or breach at any of them could ripple across underwriting, claims and payments systems at once. It doesn't make the cloud providers regulated financial firms, but regulators can now demand information and push for resilience changes directly, rather than leaving each bank to chase its supplier alone.
And a reminder that supply chain risk cuts in unexpected directions: Jscrambler, a JavaScript security vendor, had its own npm package backdoored on 11 July after a stolen publishing credential let an attacker push five malicious versions. The payload, a Rust infostealer built on the same IronWorm toolkit seen in an earlier npm campaign, harvested AWS, Azure and Google Cloud credentials, password managers and, tellingly, the stored keys of AI coding assistants including Claude Desktop and Cursor. A security vendor's own build pipeline is precisely the kind of link a patient attacker wants to compromise.
Sources
- Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
- Arista patches VeloCloud Orchestrator zero-day exploited in attacks
- Cookie Crumbles: How Exploitation of CVE-2026-0257 Leads to Qilin Ransomware
- Critical Third Parties Regime Goes Live: Cloud Giants Named
- Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install
- The Streak Continues: Four More Supply Chain Attacks Hit npm and PyPI
If you'd like to talk through what any of this means for your own systems, get in touch.
More like this
- A trusted GitHub workflow, and the three million downloads it poisoned 15 july 2026
- The npm maintainer account North Korea phished, and the four packages it unlocked 31 july 2026
- A mislabelled maintenance job, and the outage it exported to Britain 27 july 2026
Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.