Breaking: Three Actively Exploited Infrastructure Vulnerabilities — Arista VeloCloud (CVSS 10.0), N-able N-central, and Check Point SmartConsole — 4 August 2026
Arista VeloCloud Command Injection (CVSS 10.0), N-able N-central Auth Bypass, and Check Point SmartConsole Zero-Day: Three Actively Exploited Infrastructure Vulnerabilities
Arista VeloCloud Orchestrator — CVE-2026-16812
Arista has disclosed a maximum-severity OS command injection vulnerability in VeloCloud Orchestrator (VCO) on-premises deployments. CVE-2026-16812 carries a CVSS score of 10.0 and is confirmed as actively exploited in the wild. The flaw allows an unauthenticated remote attacker to execute arbitrary OS commands, gaining access to privileged internal functions on the VCO host. Successful exploitation can compromise the confidentiality, integrity, and availability of the orchestrator and all data it manages, including SD-WAN configuration for every edge device in the fleet.
CISA added the vulnerability to the KEV catalog on July 27 with a three-day remediation deadline of July 30 under BOD 26-04. Arista's advisory (Security Advisory 0144) confirms active exploitation. Any organisation running VeloCloud Orchestrator on-premises should verify patch status immediately.
N-able N-central — CVE-2026-18577
N-able has confirmed active exploitation of an authentication bypass in its N-central remote monitoring and management platform. CVE-2026-18577 (CVSS 8.2) is the result of an incomplete fix for CVE-2026-18556. An unauthenticated attacker can bypass authentication and gain administrative access to the N-central server, then use the built-in Take Control feature to reach managed downstream endpoints.
Huntress has observed exploitation across multiple organisations. Attackers enumerated running processes on domain controllers and other key servers, moved laterally across multiple hosts, and in some cases installed Cloudflare tunnels as persistent services that survive reboots and need no inbound firewall rules. N-able has released build 2026.3.1.7 as the first fully patched version. Build 2026.3 alone is insufficient. The 2026.2 fix for the original CVE-2026-18556 is also insufficient.
Every N-central customer, whether hosted or self-hosted, should upgrade to 2026.3.1.7 immediately, audit Take Control session logs for unrecognised MSP Support connections, and hunt for Cloudflared services and svchost.exe in user Documents folders on managed endpoints. Self-hosted servers are particularly at risk, with 28.6% still unpatched as of August 3.
Check Point SmartConsole — CVE-2026-16232
CISA added CVE-2026-16232 (CVSS 9.3) to the KEV catalog on July 22 with a three-day remediation deadline of July 25. This is an authentication bypass in the SmartConsole login process affecting Security Management Server and Multi-Domain Security Management Server in releases R81.20, R82, and R82.10. An unauthenticated remote attacker with network access can obtain a login token and authenticate with full administrative privileges, potentially taking over the entire security management infrastructure, altering firewall policies, creating privileged accounts, and pivoting into managed environments.
Check Point has released Jumbo Hotfix Accumulator patches. Smart-1 Cloud customers are already protected. Until patches are deployed, restrict Trusted Clients in SmartConsole to approved administrative IP addresses and subnets, and ensure management interfaces are never exposed to untrusted networks.
So What / Action
Three actively exploited vulnerabilities targeting security and management infrastructure within a single week is unusual and concerning. Each of these products sits at a control-plane choke point: SD-WAN orchestration, endpoint management, and firewall policy management. A compromise at any of these layers gives an attacker leverage over the entire downstream environment.
Patch immediately if you run any of these products. For N-central specifically, the incomplete first patch means you must verify you are on build 2026.3.1.7, not just 2026.3. For Check Point, restrict management access to trusted IPs now and apply the Jumbo Hotfix. For Arista VeloCloud, check your on-prem orchestrator version against Arista's advisory and patch if you have not already passed the July 30 KEV deadline.
Beyond patching, audit for indicators of compromise. Each of these vulnerabilities has been exploited in the wild, and the window between initial exploitation and discovery may have been days or weeks.


Focusing on these infrastructure vulnerabilities highlights how the management layer has become the primary target for attackers. When the tools designed to orchestrate our security posture are compromised, the perimeter effectively ceases to exist. This shift confirms that protecting the console is now as critical as protecting the endpoints themselves, because the console that writes your security policy is now the way in. We are seeing a fundamental change in how attackers prioritize their targets, moving away from individual machines toward the central nervous system of the enterprise. By securing these administrative interfaces, we protect the very mechanisms that define our defense.
https://cyrilsimonnet.substack.com/p/substack-paste-ready