Security · 22h ago
Arista Patches Actively Exploited VeloCloud Bug; CISA Sets Deadline
Arista Networks has patched a critical unauthenticated command injection vulnerability in its VeloCloud SD-WAN edge devices, scoring a perfect 10 on the CVSS scale. CISA has added the flaw to its Known Exploited Vulnerabilities catalog, giving federal agencies until August 17 to remediate. The bug is being actively exploited in the wild, potentially exposing managed edge devices to full compromise.
Meridian48 take
The perfect CVSS score and active exploitation underscore the urgency, but the real test is whether enterprises can patch thousands of distributed edge devices before attackers widen their foothold.
Read the full reporting
Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock →
The Register
arista-velocloudcisa-deadline