← Back

Wire · technology

Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock

Published

28 July 2026

Topic

technology

Sectors

Cybersecurity

Geography

United States

Source

Read at theregister.com

Verified

Fusion42 · 28 July 2026 · Fusion42 review

Arista has released a patch for a critical unauthenticated command injection vulnerability in VeloCloud (CVSS 10.0) that is already being actively exploited. CISA has issued a deadline for administrators to apply the patch, affecting managed Edge devices across deployments.

This Wire brief sits within Fusion42's coverage of Cybersecurity. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur reasons over.

◆ The Wire takeaway

A perfect-10 vulnerability in Arista's edge networking gear is already being weaponised. If you build security monitoring or breach response tooling for enterprise networks, your inbound will spike this week—get your response playbooks ready now.

Related on Wire

Topics

Cybersecurityactive-exploitzero-daycritical-patchedge-infrastructurecommand-injection