CyberHighConfirmedDeveloping
10.0
Critical pre-auth RCE vulnerability identified in OpenWrt DHCPv6 service
The Hacker News·about 11 hours ago
Threat actors are actively exploiting a CVSS 10.0 command injection vulnerability in on-premises Arista VeloCloud Orchestrator instances. The flaw allows unauthorized remote code execution, potentially granting attackers control over downstream managed Edge devices. CISA has mandated federal agencies to apply patches by July 30, 2026.