Cyber Threat Brief — July 28 2026

⚠️ This report is AI-generated. Always validate findings.

1. Arista VeloCloud Orchestrator Unauth RCE — CVE-2026-16812

TL;DR: CVSS 10.0 unauthenticated OS command injection in on-premises VeloCloud Orchestrator is under active exploitation and was added to CISA KEV July 27 with a July 30 federal deadline. Compromised VCO pivots to all managed SD-WAN edge devices.

What’s New:

  • CISA KEV addition July 27; FCEB deadline July 30 (Wednesday)
  • Unauth command injection via internal-only functionality left remotely accessible (CWE-78)
  • No credentials, no user interaction required; network access to VCO web interface is sufficient
  • Arista has not disclosed attribution, exploitation timeline, or IOCs
  • Hosted and Dedicated VCO deployments were pre-patched; only on-prem is affected

Actionable Intel

ArtifactTypeATT&CKLog SourceAction
VCO web interface (on-prem)Attack surfaceT1190Firewall logsRestrict access to management VLAN
VCO < 5.2.3.14 / 6.1.3.4 / 6.4.2.4Vulnerable versionsT1190Asset inventoryPatch immediately
Anomalous OS commands from VCO processPost-exploitationT1059EDR / auditdHunt
VeloCloud Edge config changesLateral movementT1021SD-WAN controller logsAudit

Detection

SourceRuleGap
Splunk ESCUNoneNo VeloCloud-specific detection; need web server spawning shell rule tuned for VCO
ElasticNoneNo coverage
SigmaNoneNo coverage; need rule for anomalous process execution on VCO host

Sources: BleepingComputer, The Hacker News, CISA KEV July 27, Arista SA-0144

2. JetBrains TeamCity Pre-Auth Deserialization RCE — CVE-2026-63077

TL;DR: CVSS 9.8 unauthenticated RCE in all TeamCity On-Premises versions via insecure deserialization in the agent polling protocol; patches dropped July 27 — expect rapid weaponization given TeamCity’s exploitation history.

What’s New:

  • Disclosed and patched July 27; affects all TeamCity On-Premises versions
  • Insecure deserialization of untrusted data (CWE-502) in agent polling protocol
  • Unauthenticated attacker with HTTP(S) access bypasses auth and executes OS commands
  • Fixed in 2025.11.7 and 2026.1.3; security patch plugin for 2017.1+
  • TeamCity Cloud not affected; privately reported July 10 by Antoni Tremblay

Actionable Intel

ArtifactTypeATT&CKLog SourceAction
TeamCity agent polling endpointAttack surfaceT1190WAF/proxy logsMonitor for anomalous serialized payloads
TeamCity < 2025.11.7 / 2026.1.3Vulnerable versionsT1190Asset inventoryPatch or apply plugin immediately
Unexpected child processes from TeamCity servicePost-exploitationT1059EDR / SysmonHunt
Outbound connections from TeamCity serverC2 indicatorT1071Firewall/proxy logsBaseline and alert

Detection

SourceRuleGap
Splunk ESCUNoneNo TeamCity-specific detection; need Java process spawning shell rule tuned for TeamCity service
ElasticWeb Shell Detection: Script Process Child of Common Web Processes (partial)Not tuned for TeamCity agent protocol
SigmaSuspicious Java Process Spawning Shell (generic)Needs TeamCity process name tuning

Sources: JetBrains Blog, The Hacker News

3. Certighost AD CS PoC Updated — CVE-2026-54121

TL;DR: The public Certighost PoC received July 28 updates that fix reliability issues against CAs co-hosted on DCs — expect broader exploitation of this CVSS 8.8 AD CS domain takeover flaw now that the tooling works out-of-the-box.

What’s New:

  • PoC updated July 28: in-script hotpatch of rogue SMB NetLogon path ensures exploit works when CA is on a DC
  • Fix for request-supplied SANs avoids KDC_ERR_CLIENT_NAME_MISMATCH errors
  • SOCPrime released detection content for Certighost abuse; Sigma TargetImage logic triggers EID 5154/5156
  • Microsoft Defender generates “Potential Certighost (CVE-2026-54121) AD CS abuse” alert
  • Patched July 14 Patch Tuesday; exploitation requires low-priv domain account + network access

Actionable Intel

ArtifactTypeATT&CKLog SourceAction
Certificate request with cdc attributeExploitationT1649AD CS audit logs (EID 4886/4887)Alert on non-standard attributes
Rogue LDAP listener on port 389 from non-DC hostExploitationT1557Network flow / firewallBlock/Alert
DCSync (EID 4662 with DS-Replication-Get-Changes)Post-exploitationT1003.006Windows Security logAlert
certighost.py process or SMB listenerPoC toolT1649EDR / SysmonHunt

Detection

SourceRuleGap
Splunk ESCUDCSync Activity (EID 4662)Misses certificate-based pre-DCSync path; need CA enrollment anomaly rule
ElasticActive Directory Certificate Services AbusePartial — detects DCSync stage only
Sigmawin_security_dcsync_attack.ymlCovers DCSync but not cert issuance with cdc attribute anomaly

Sources: Help Net Security, SOCPrime, GitHub PoC

TL;DR: CISA KEV addition July 27 for a FortiOS information disclosure that lets attackers bypass a previous symlink persistence fix — requires prior filesystem access via a separate vulnerability but enables read-only access to sensitive data on patched appliances.

What’s New:

  • CISA KEV addition July 27 alongside CVE-2026-16812
  • Bypasses previously patched symbolic link persistency mechanism via crafted HTTP requests
  • Affects FortiOS 7.6.0-7.6.1, 7.4.0-7.4.6, all 7.2.x/7.0.x/6.4.x
  • Requires prior filesystem-level access (not standalone exploitable)
  • Chained with initial access vulns for persistent read access post-patch

Actionable Intel

ArtifactTypeATT&CKLog SourceAction
Symbolic links in FortiOS filesystemPersistenceT1547FortiOS system integrity checkRun Fortinet integrity verification tool
FortiOS < 7.6.2 / 7.4.7Vulnerable versionsT1190Asset inventoryPatch or verify no prior compromise
Anomalous HTTP requests to management planeExploitationT1190FortiOS traffic logsHunt

Detection

SourceRuleGap
Splunk ESCUNone specificNeed FortiOS integrity violation detection
ElasticNoneNo coverage
SigmaNoneNo coverage; need rule for FortiOS symlink persistence indicators

Sources: Security Affairs, CISA KEV July 27


Status Updates

  • CVE-2026-56155 (AD FS EoP): Federal CISA KEV deadline TODAY July 28. Zero-day exploitation ongoing. Patch via July 14 Patch Tuesday. Original brief.
  • CVE-2026-12569 (PTC Windchill/FlexPLM): Cl0p extortion campaign ongoing via support@cryptohox[.]com. JSP webshells and flst.txt recon active. Original brief.
  • CVE-2026-6875 (ServiceNow): Active exploitation ongoing since July 18. Two sandbox-escape gadget chains confirmed. Fortune 500 victims. Still not on CISA KEV. Original brief.
  • CVE-2026-50522 (SharePoint Deserialization): Federal deadline passed July 25. Active exploitation via BinaryFormatter at /_trust/default.aspx. Machine key theft for persistence. Original brief.
  • CVE-2026-16232 (Check Point SmartConsole): Federal deadline passed July 25. Zero-day auth bypass exploitation ongoing. Original brief.