Categories Uncategorized

Weekly Exploit Roundup 2026-07-28

Weekly Exploit Roundup

Generated 2026-07-28T08:00:10.468601+00:00 (UTC)

  1. Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
    Source: CISA Cybersecurity Advisories | Published: 2026-07-21T19:08:02+00:00 | Score: 23.631
    Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite Executive summary A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS) software since at least July 2025. The Russian state-supported advanced persistent threat (APT) group’s activity is tracked in the cybersecurity community under several names (see Cybersecurity industry tracking ), primarily as “LAUNDRY BEAR,” a name initially coined by the Netherlands General Intelligence and Security Service (AIVD) and Defence Intelligence and Security Service (MIVD) [ 1 ]. LAUNDRY BEAR’s targeting is almost certainly to gather sensitive information for the Russian Federation, with these actors primarily focusing on the covert acquisition of email data. Previous campaigns indicated LAUNDRY BEAR relied on unsophisticated initial access techniques—including passwor
  2. Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
    Source: The Hacker News | Published: 2026-07-28T04:43:53+00:00 | Score: 22.003
    A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild.

    The vulnerability, tracked as CVE-2026-16812 (CVSS score: 10.0), is a case of operating system command injection that could pave the way for arbitrary code execution.

    "VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue

  3. Hackers target US firms in FastJson RCE zero-day attacks
    Source: BleepingComputer | Published: 2026-07-27T23:49:44+00:00 | Score: 21.457
    Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges. […]
  4. Arista patches VeloCloud Orchestrator zero-day exploited in attacks
    Source: BleepingComputer | Published: 2026-07-27T22:49:44+00:00 | Score: 21.427
    Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks. […]
  5. CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild
    Source: Rapid7 Cybersecurity Blog | Published: 2026-07-23T11:57:30+00:00 | Score: 20.046
    Overview On July 22, 2026, Check Point published a security advisory for multiple vulnerabilities affecting Security Management, Multi-Domain Management, and firewall products. The most urgent of these is CVE-2026-16232 , an authentication bypass in the SmartConsole login process classified as improper authentication ( CWE-287 ). CVE-2026-16232 has been assigned a critical CVSS score of 9.1. The vulnerability allows an unauthenticated remote attacker to obtain an application login token and authenticate to the management server with full administrative privileges, enabling modification of security policies and configurations. Check Point has confirmed that CVE-2026-16232 is being actively exploited in the wild, affecting what the vendor describes as a small number of customers. Remote exploitation requires network access to the Management Server IP address in environments that do not restrict Trusted Clients. On the same day as the advisory, CVE-2026-16232 was added to the U.S. Cyberse
  6. Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day
    Source: SecurityWeek | Published: 2026-07-28T06:40:36+00:00 | Score: 19.961
    Impacting on-premises deployments, the OS command injection allows attackers to access privileged internal functionality. The post Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day appeared first on SecurityWeek .
  7. CISA Adds Two Known Exploited Vulnerabilities to Catalog
    Source: Alerts | Published: 2026-07-27T12:00:00+00:00 | Score: 19.905
    CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2025-68686 Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability CVE-2026-16812 Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, w
  8. Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
    Source: The Hacker News | Published: 2026-07-22T12:36:36+00:00 | Score: 18.451
    A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck.

    The vulnerability in question is CVE-2026-29059 (CVSS score: 7.5), a case of unauthenticated path traversal impacting Windmill's "get_log_file" endpoint ("/api/w/{workspace}/jobs_u/get_log_file/{filename}").

    "The filename parameter is concatenated into

  9. Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say
    Source: The Hacker News | Published: 2026-07-24T06:58:27+00:00 | Score: 17.712
    Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0.

    All four chains require RESTORE. The Streams chains also need EVAL and XGROUP; the 8.8.0 chain needs EVAL and the bundled RedisBloom module. Redis says the underlying memory flaws may lead to remote code execution.

    Redis 6.2.23, 7.2.15, and 7.4.10

  10. CISA Adds Two Known Exploited Vulnerabilities to Catalog
    Source: Alerts | Published: 2026-07-22T12:00:00+00:00 | Score: 17.633
    CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-16232 Check Point SmartConsole Improper Authentication Vulnerability CVE-2026-50522 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower

End of report.

Written By

More From Author

You May Also Like