CRITICAL 7 min read 29 Jul 2026

Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day Leads Today's Security Review

Executive assessment Today's brief leads with Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day. All 15 selected findings retain their own technical scope, action, observed status, and evidence limits.

Key findings
01
Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day
CRITICAL
Impacting on-premises deployments, the OS command injection allows attackers to access privileged internal functionality. The post Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day appeared first on SecurityWeek . The assigned identifier is CVE-2026-16812.
02
Chromium: CVE-2026-13032 Use after free in WebGL
CRITICAL
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. The assigned identifier is CVE-2026-13032.
03
Chromium: CVE-2026-13028 Use after free in WebGL
CRITICAL
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. The assigned identifier is CVE-2026-13028.
04
CVE-2026-54658: @hypequery/clickhouse has SQL Injection in parameter escaping that allows…
CRITICAL
@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution CVE coverage: CVE-2026-54658. Sources: - https://github.com/advisories/GHSA-6wcc-39rp-hh9p
05
CVE-2026-62325: goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-…
CRITICAL
goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884) CVE coverage: CVE-2026-62325, CVE-2026-40884. Sources: - https://github.com/advisories/GHSA-rjrw-mjq6-hpmm
06
CVE-2026-54638: td has pre-auth denial of service via unbounded memory allocation in proto.Unenc…
HIGH
td has pre-auth denial of service via unbounded memory allocation in proto.UnencryptedMessage.Decode CVE coverage: CVE-2026-54638. Sources: - https://github.com/advisories/GHSA-whmm-qj9r-wvr2
07
Chromium: CVE-2026-13037 Use after free in WebView
HIGH
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. The assigned identifier is CVE-2026-13037.
08
CVE-2026-54639: Style Dictionary - Prototype Pollution in convertTokenData utility function
HIGH
Style Dictionary - Prototype Pollution in convertTokenData utility function CVE coverage: CVE-2026-54639. Sources: - https://github.com/advisories/GHSA-vj5c-m527-mpff
09
CVE-2026-54650: openhole-server vulnerable to path traversal via URL-decoded request path
HIGH
openhole-server vulnerable to path traversal via URL-decoded request path CVE coverage: CVE-2026-54650. Sources: - https://github.com/advisories/GHSA-fh2f-xfxc-q9cc
10
Chromium: CVE-2026-13030 Uninitialized Use in GPU
MEDIUM
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. The assigned identifier is CVE-2026-13030.
11
CVE-2026-66064: goshs has ACL Bypass & Path Traversal
MEDIUM
goshs has ACL Bypass & Path Traversal CVE coverage: CVE-2026-66064. Sources: - https://github.com/advisories/GHSA-964w-f6gj-5236
12
CVE-2026-54659: Pagy I18n locale option is not validated before being used in a file path
MEDIUM
Pagy I18n locale option is not validated before being used in a file path CVE coverage: CVE-2026-54659. Sources: - https://github.com/advisories/GHSA-2xmw-f8j8-wfxc
13
CVE-2026-66063: goshs has a Path Traversal issue
MEDIUM
goshs has a Path Traversal issue CVE coverage: CVE-2026-66063. Sources: - https://github.com/advisories/GHSA-wg2q-39h6-66x9
14
Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock
INFO
Unauthenticated command injection scores perfect 10 and may expose managed Edge devices CVE coverage: none. Sources: - https://www.theregister.com/security/2026/07/28/arista-patches-actively-exploited-velocloud-bug-as-cisa-puts-admins-on-the-clock/5279414
15
JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach
INFO
JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation environment. Artifactory is JFrog's software repository manager.

Executive assessment

Today's brief leads with Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day. All 15 selected findings retain their own technical scope, action, observed status, and evidence limits.

Finding 01 — Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day

What changed: Impacting on-premises deployments, the OS command injection allows attackers to access privileged internal functionality. The post Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day appeared first on SecurityWeek .

Technical evidence: CVE-2026-16812; CVSS v3.1 10; weakness ['CWE-78']; technical confidence High.

Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.

Observed status: Observed in-the-wild exploitation is confirmed.

Action: Map CVE-2026-16812 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

affected product not structured

[Evidence source: thehackernews.com](<https://thehackernews.com/2026/07/attackers-exploit-arista-velocloud.html>)

Finding 02 — Chromium: CVE-2026-13032 Use after free in WebGL

What changed: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability.

Technical evidence: CVE-2026-13032; CVSS v3.1 9.6; weakness ['CWE-416']; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-13032 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: chromereleases.googleblog.com](<https://chromereleases.googleblog.com/2026>)

Finding 03 — Chromium: CVE-2026-13028 Use after free in WebGL

What changed: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability.

Technical evidence: CVE-2026-13028; CVSS v3.1 9.6; weakness ['CWE-416']; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-13028 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: chromereleases.googleblog.com](<https://chromereleases.googleblog.com/2026>)

Finding 04 — CVE-2026-54658: @hypequery/clickhouse has SQL Injection in parameter escaping that allows…

What changed: @hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution CVE coverage: CVE-2026-54658. Sources: - https://github.com/advisories/GHSA-6wcc-39rp-hh9p

Technical evidence: CVE-2026-54658; CVSS v3.1 9.8; weakness ['CWE-89']; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-54658 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: github.com](<https://github.com/advisories/GHSA-6wcc-39rp-hh9p>)

Finding 05 — CVE-2026-62325: goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-…

What changed: goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884) CVE coverage: CVE-2026-62325, CVE-2026-40884. Sources: - https://github.com/advisories/GHSA-rjrw-mjq6-hpmm

Technical evidence: CVE-2026-62325; CVSS v3.1 9.1; weakness ['CWE-306']; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-62325 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: github.com](<https://github.com/advisories/GHSA-rjrw-mjq6-hpmm>)

Finding 06 — CVE-2026-54638: td has pre-auth denial of service via unbounded memory allocation in proto.Unenc…

What changed: td has pre-auth denial of service via unbounded memory allocation in proto.UnencryptedMessage.Decode CVE coverage: CVE-2026-54638. Sources: - https://github.com/advisories/GHSA-whmm-qj9r-wvr2

Technical evidence: CVE-2026-54638; CVSS v3.1 7.5; weakness ['CWE-770', 'CWE-789']; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-54638 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: github.com](<https://github.com/advisories/GHSA-whmm-qj9r-wvr2>)

Finding 07 — Chromium: CVE-2026-13037 Use after free in WebView

What changed: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability.

Technical evidence: CVE-2026-13037; CVSS v3.1 7.8; weakness ['CWE-416']; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-13037 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: chromereleases.googleblog.com](<https://chromereleases.googleblog.com/2026>)

Finding 08 — CVE-2026-54639: Style Dictionary - Prototype Pollution in convertTokenData utility function

What changed: Style Dictionary - Prototype Pollution in convertTokenData utility function CVE coverage: CVE-2026-54639. Sources: - https://github.com/advisories/GHSA-vj5c-m527-mpff

Technical evidence: CVE-2026-54639; CVSS v3.1 8.8; weakness ['CWE-1321']; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-54639 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: github.com](<https://github.com/advisories/GHSA-vj5c-m527-mpff>)

Finding 09 — CVE-2026-54650: openhole-server vulnerable to path traversal via URL-decoded request path

What changed: openhole-server vulnerable to path traversal via URL-decoded request path CVE coverage: CVE-2026-54650. Sources: - https://github.com/advisories/GHSA-fh2f-xfxc-q9cc

Technical evidence: CVE-2026-54650; CVSS v3.1 8.6; weakness ['CWE-22']; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-54650 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: github.com](<https://github.com/advisories/GHSA-fh2f-xfxc-q9cc>)

Finding 10 — Chromium: CVE-2026-13030 Uninitialized Use in GPU

What changed: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability.

Technical evidence: CVE-2026-13030; CVSS v3.1 5.3; weakness ['CWE-457']; technical confidence High.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-13030 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: chromereleases.googleblog.com](<https://chromereleases.googleblog.com/2026>)

Finding 11 — CVE-2026-66064: goshs has ACL Bypass & Path Traversal

What changed: goshs has ACL Bypass & Path Traversal CVE coverage: CVE-2026-66064. Sources: - https://github.com/advisories/GHSA-964w-f6gj-5236

Technical evidence: CVE-2026-66064; CVSS v3.1 5.3; weakness ['CWE-41', 'CWE-863']; technical confidence High.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-66064 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: github.com](<https://github.com/advisories/GHSA-964w-f6gj-5236>)

Finding 12 — CVE-2026-54659: Pagy I18n locale option is not validated before being used in a file path

What changed: Pagy I18n locale option is not validated before being used in a file path CVE coverage: CVE-2026-54659. Sources: - https://github.com/advisories/GHSA-2xmw-f8j8-wfxc

Technical evidence: CVE-2026-54659; CVSS v4.0 6.9; weakness ['CWE-22', 'CWE-200']; technical confidence High.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-54659 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: github.com](<https://github.com/advisories/GHSA-2xmw-f8j8-wfxc>)

Finding 13 — CVE-2026-66063: goshs has a Path Traversal issue

What changed: goshs has a Path Traversal issue CVE coverage: CVE-2026-66063. Sources: - https://github.com/advisories/GHSA-wg2q-39h6-66x9

Technical evidence: CVE-2026-66063; CVSS v3.1 6.5; weakness ['CWE-22']; technical confidence High.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-66063 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: github.com](<https://github.com/advisories/GHSA-wg2q-39h6-66x9>)

Finding 14 — Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock

What changed: Unauthenticated command injection scores perfect 10 and may expose managed Edge devices CVE coverage: none. Sources: - https://www.theregister.com/security/2026/07/28/arista-patches-actively-exploited-velocloud-bug-as-cisa-puts-admins-on-the-clock/5279414

Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.

Observed status: The cited source reports active in-the-wild exploitation; independent corroboration (CISA KEV or grounded vendor data) is not yet available.

Action: Review the cited source, validate exposure of the affected technology in owned environments, apply available vendor guidance, and retain evidence of the exposure decision.

Evidence limits: grounded severity unavailable

exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: www.theregister.com](<https://www.theregister.com/security/2026/07/28/arista-patches-actively-exploited-velocloud-bug-as-cisa-puts-admins-on-the-clock/5279414>)

Finding 15 — JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach

What changed: JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation environment. Artifactory is JFrog's software repository manager.

Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.

Observed status: The cited source reports active in-the-wild exploitation; independent corroboration (CISA KEV or grounded vendor data) is not yet available.

Action: Review the cited source, validate exposure of the affected technology in owned environments, apply available vendor guidance, and retain evidence of the exposure decision.

Evidence limits: grounded severity unavailable

exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: thehackernews.com](<https://thehackernews.com/2026/07/jfrog-confirms-openai-models-exploited.html>)

cve-2026-13028cve-2026-13030cve-2026-13032cve-2026-13037cve-2026-16812cve-2026-54638cve-2026-54639cve-2026-54650cve-2026-54658cve-2026-54659

Act on this brief

Map detection coverage gaps for the techniques above, or generate Sigma rules from the named CVEs.