Arista patches actively exploited VeloCloud Orchestrator zero-day
2026-09-23T13:23:22Z•9619d5e43db368255b0c8db3d5a4820ab1b645c21a5358131e57f0650405b464
CVE-2026-86296AI-enabled malwareCheck PointChinese-speaking threat actorD-LinkF5 BIG-IPMFA bypassRyukShinyHuntersVPN disruptionVeloCloud OrchestratorWindows DefenderWordPressZyxelactively exploited zero-daycredential theftdata breachnetwork appliancesphishing-as-a-serviceransomwareremote code executionvulnerability management
What happened
BleepingComputer security feed covering multiple high-impact developments, including actively exploited zero-day vulnerabilities in Arista VeloCloud Orchestrator, F5 BIG-IP APM, and Check Point Security Management Server; a critical unpatched D-Link DIR-822A flaw with public proof of concept; exploitation of Zyxel and WordPress weaknesses; credential theft via rogue MFA providers; ransomware and extortion activity; AI-assisted malware; and disruption of an MFA phishing-as-a-service operation.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 9619d5e43db368255b0c8db3d5a4820ab1b645c21a5358131e57f0650405b464
- Enrichment time
- 2026-09-23T13:23:22Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.