[{"id":"EUVD-2026-50404","enisaUuid":"1b67464c-342a-33a5-a841-1b542494100c","description":"A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.\r\n\r\nThis vulnerability is due to the presence of static user credentials for a low-privileged\u0026nbsp;account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user.\u0026nbsp;\r\nNote:\u0026nbsp;If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.\u0026nbsp;\u0026nbsp;\r\nCisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges.","datePublished":"Jul 29, 2026, 4:22:08 PM","dateUpdated":"Jul 29, 2026, 7:58:23 PM","baseScore":5.3,"baseScoreVersion":"3.1","baseScoreVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","references":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh\n","aliases":"GHSA-x85f-hvgg-4944\nCVE-2026-20316\n","assigner":"cisco","epss":0.0,"exploitedSince":"Jul 29, 2026, 12:00:00 AM","enisaIdVendor":[{"id":"815e7e86-a862-374e-b847-1a25bf98f9a9","vendor":{"name":"Cisco"}}]},{"id":"EUVD-2026-49334","enisaUuid":"583902e4-b23c-38cd-a228-4b95564f377c","description":"VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.\n\n\n\n\nThis functionality was intended to be for internal use only and is not intended to be remotely accessible.\n\n\n\n\nHosted and Dedicated versions of VCO have already been patched in advance of this notice going out.\n\n\n\n\nThis issue was discovered externally and is known to be actively exploited.","datePublished":"Jul 27, 2026, 4:11:00 PM","dateUpdated":"Jul 28, 2026, 3:56:40 AM","baseScore":10.0,"baseScoreVersion":"4.0","baseScoreVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/S:P","references":"https://www.arista.com/en/support/advisories-notices/security-advisory/24364-security-advisory-0144\n","aliases":"CVE-2026-16812\nGHSA-f2cp-q2qv-6563\n","assigner":"Arista","epss":0.98,"exploitedSince":"Jul 27, 2026, 12:00:00 AM","enisaIdVendor":[{"id":"eb9a12d3-cacd-3f26-92dd-ce23e87d2c6e","vendor":{"name":"Arista Networks"}}]},{"id":"EUVD-2025-207440","enisaUuid":"8c42044a-4460-3a78-ab39-0488b6d33628","description":"An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.","datePublished":"Feb 10, 2026, 3:39:12 PM","dateUpdated":"Jul 28, 2026, 3:55:36 AM","baseScore":5.3,"baseScoreVersion":"3.1","baseScoreVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C","references":"https://fortiguard.fortinet.com/psirt/FG-IR-25-934\n","aliases":"GHSA-839g-m33x-3w78\nCVE-2025-68686\n","assigner":"fortinet","epss":1.26,"exploitedSince":"Jul 27, 2026, 12:00:00 AM","enisaIdVendor":[{"id":"2e30caf8-f830-3386-8bfe-93d4106aabc1","vendor":{"name":"Fortinet"}}]},{"id":"EUVD-2026-47700","enisaUuid":"d76da256-fe6a-375d-a1ed-887f91e612f2","description":"An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.","datePublished":"Jul 22, 2026, 1:53:09 PM","dateUpdated":"Jul 23, 2026, 3:55:51 AM","baseScore":9.1,"baseScoreVersion":"3.1","baseScoreVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","references":"https://support.checkpoint.com/results/sk/sk185169\n","aliases":"CVE-2026-16232\nGHSA-m2xx-23gx-734v\n","assigner":"checkpoint","epss":12.69,"exploitedSince":"Jul 22, 2026, 12:00:00 AM","enisaIdVendor":[{"id":"b02ade41-c846-35e8-ac96-b1dd56682d78","vendor":{"name":"checkpoint"}}]}]