Two edge-infrastructure flaws reached CISA's exploited-vulnerabilities list within three days of each other this week, one in Arista's VeloCloud SD-WAN orchestrator with the maximum possible severity score, the other a zero-day credential baked into Cisco's firewall management console. Closer to home, Bank of Baroda is investigating a compromised employee mailbox after a dark-web listing claimed a terabyte of customer data, and ransomware affiliates have turned a Palo Alto VPN authentication flaw into a standard entry point. Washington's updated advisory on Iranian PLC intrusions is a reminder that the industrial hardware named in it runs a good share of Indian power, water and manufacturing plants too.
1CriticalCVSS 10.0
Arista VeloCloud Orchestrator Command Injection Under Active Exploitation — CVE-2026-16812
CVSS 10.0 (maximum severity) | CISA KEV, 27 July — remediation due 30 July* Arista disclosed CVE-2026-16812 on 27 July 2026, an unauthenticated OS command-injection flaw in on-premises deployments of VeloCloud Orchestrator (VCO), the management controller for its SD-WAN fleet. The bug lets a remote attacker reach privileged, internally-intended functionality without any credentials, and Arista confirmed it was already being exploited before the advisory shipped. Affected release trains span VCO 5.2.x, 6.1.x, 6.4.x and 7.0.x before their respective fixed builds; Arista's own Hosted and Dedicated VCO offerings were patched ahead of disclosure and are not affected, nor are the separate VeloCloud Gateway and Edge products. CISA added the flaw to its Known Exploited Vulnerabilities catalogue the same day, with a federal remediation deadline of 30 July.
India exposureVeloCloud is one of the SD-WAN platforms enterprises and telecom providers in India run for branch and multi-site connectivity, and it is the self-managed, on-premises VCO installations, not Arista's own hosted tier, that carry the risk. A compromised orchestrator gives an attacker visibility and control across every branch site it manages.
ActionUpgrade on-premises VCO to 5.2.3.14, 6.1.3.4, 6.4.2.4 or 7.0.0.1 or later immediately. Until patched, restrict orchestrator management access to trusted administrative networks, and review orchestrator logs for command execution or configuration changes that do not match known change windows.
SourceArista Security Advisory 0144, 27 July 2026; CISA KEV, 27 July 2026; BleepingComputer, 28 July 2026; SecurityWeek, 27-28 July 2026.
2MediumCVSS 5.3
Cisco Secure Firewall Management Center Hard-Coded Credential Exploited as Zero-Day — CVE-2026-20316
CVSS 5.3, High Security Impact Rating (Cisco) | CISA KEV, 29 July — remediation due 1 August* Cisco disclosed CVE-2026-20316 on 29 July 2026 after its own PSIRT found evidence of exploitation before a fix existed. A static, low-privilege credential built into the Secure Firewall Management Center (FMC) web interface lets an unauthenticated attacker, anywhere on the network or the open internet, log in without valid credentials. The access granted is limited on its own, but Cisco rates the issue High Security Impact because that foothold can be combined with other FMC flaws, including a separate critical authentication-bypass issue, to reach far greater control. CISA added the CVE to its Known Exploited Vulnerabilities catalogue the same day, with a federal remediation deadline of 1 August. Cloud-Delivered FMC, Firepower Device Manager, Secure Firewall ASA and Threat Defense software are not affected.
India exposureCisco's Secure Firewall line, including FMC, sits behind a wide base of enterprise and government network deployments in India. Any internet-reachable FMC console is exposed regardless of sector, and the chainable nature of this flaw with other FMC bugs raises the stakes beyond its own limited CVSS score.
ActionApply Cisco's fixed software; there is no workaround for a static credential. Take FMC management interfaces off the open internet, restrict access to trusted management networks or VPN-only paths, and audit web-interface authentication logs for activity from the low-privilege account outside expected administrative windows.
SourceCisco Security Advisory, 29 July 2026; CISA KEV, 29 July 2026; BleepingComputer, 30 July 2026; SecurityWeek, 29-30 July 2026.
3
Bank of Baroda Investigates Compromised Mailbox After Dark-Web Listing Claims 1TB of Customer Data
No CVE | Bank-confirmed incident, disputed scope* A dark-web listing referencing Bank of Baroda surfaced on ransomware-tracking site ransomware.live around 25 July 2026, claiming roughly a terabyte of data including customer names, Aadhaar numbers, loan records, branch audit files and internal correspondence. Bank of Baroda confirmed on 27-28 July that an employee's email account had been compromised, resulting in unauthorised access to "certain data," while stating that core banking systems were not accessed and remain secure. The bank said a comprehensive forensic investigation is under way with relevant authorities. No group has claimed the incident through an official channel; a researcher tracking the listing has floated a possible link to a group called TripleX, previously associated with a large Indonesian bank breach, but this is speculative and the bank has not confirmed any attribution.
India exposureThis is a direct, bank-confirmed incident at one of India's largest public-sector banks. Even with the claimed data volume and contents unverified beyond the bank's own statement, a single compromised staff mailbox illustrates how much customer PII, KYC material and internal audit data can sit reachable through email at an institution this size.
ActionBanks and NBFCs should extend conditional-access and phishing-resistant MFA enforcement to all employee mailboxes, not only privileged accounts, audit mail-forwarding rules and third-party OAuth app grants for anomalies, and confirm DLP coverage extends to attachments carrying KYC and Aadhaar data moving through email. Treat any leak-site data volume as unverified until an institution's own forensic findings say otherwise.
SourceBank of Baroda official statement, 27-28 July 2026, as reported by The Record and Business Today, 27 July 2026; ransomware.live listing, 25 July 2026.
CVSS 7.8 | Active exploitation reported 20-21 July 2026* Arctic Wolf Labs reported intrusions investigated through June 2026 in which Qilin ransomware affiliates used CVE-2026-0257, an authentication-bypass flaw in Palo Alto Networks PAN-OS GlobalProtect portal and gateway, as a repeatable initial-access route. The flaw lets an unauthenticated attacker forge authentication-override cookies to establish a VPN session without valid credentials, where override cookies are enabled alongside specific certificate configurations. Post-exploitation activity varied by affiliate, from fast encryption-only runs to full double-extortion operations involving credential harvesting, lateral movement over Windows admin shares, and data staged out via Rclone before ransomware deployment, consistent with several affiliates operating under the same Qilin ransomware-as-a-service umbrella.
India exposureNo named source lists an Indian victim, but GlobalProtect is a common enterprise VPN gateway across Indian BFSI, IT services and manufacturing firms of the size Qilin typically targets. Any deployment with authentication-override cookies enabled is a candidate regardless of geography.
ActionConfirm the PAN-OS patch for CVE-2026-0257 is applied, disable authentication-override cookies unless a documented business need exists, and review VPN authentication logs for sessions that bypass expected MFA prompts. Given the observed use of Rclone and Windows admin-share movement post-compromise, flag both as anomalies on any GlobalProtect-fronted network segment.
SourceArctic Wolf Labs research, reported 20-21 July 2026; Palo Alto Networks advisory; The Hacker News, 21 July 2026; Security Affairs, 21 July 2026.
5
US Agencies Expand Iranian ICS-Intrusion Advisory to Siemens and Schneider Electric PLCs — AA26-097A
No CVE | Joint advisory update, 22 July 2026* CISA, the FBI, NSA and other US agencies updated their joint advisory on Iranian-affiliated actors exploiting internet-exposed programmable logic controllers on 22 July 2026, widening it from the Rockwell Automation/Allen-Bradley devices named when the advisory first published in April to now include Siemens S7-1200 series and Schneider Electric Modicon M340 controllers. The actors, tracked under aliases including CyberAv3ngers, reach exposed PLCs directly through vendor engineering software such as Studio 5000, TIA Portal and EcoStruxure Control Expert, using it both to alter ladder logic, in one confirmed case disabling safety shutdown and alarm functions without alerting operators, and to exfiltrate PLC project files. Confirmed activity to date spans US government facilities, water and wastewater utilities and energy infrastructure.
India exposureNo source names an Indian victim in this campaign. What matters for Indian defenders is the hardware overlap: Rockwell, Siemens and Schneider Electric PLC families named in the advisory are widely deployed across Indian power distribution, water utilities and manufacturing plants, often with engineering-software access left reachable from broader plant networks.
ActionOT operators running any of the named PLC families should confirm engineering-software access is not reachable from the internet or general IT networks, enforce authentication on PLC programming ports where supported, and check the advisory's updated indicators of compromise against historical logs regardless of which regional channel the equipment was procured through.
SourceCISA advisory AA26-097A, updated 22 July 2026; SecurityWeek, 22-23 July 2026; Infosecurity Magazine, 23 July 2026.
Takeaway
This week's vendor sweep checked Fortinet, Cisco, Palo Alto Networks, Check Point, Juniper, SonicWall, Sophos, Barracuda, WatchGuard, Zscaler, Citrix NetScaler, Ivanti, F5 BIG-IP, Versa, Arista VeloCloud, Aruba/HPE EdgeConnect and Seqrite/Quick Heal by name; Fortinet also picked up a fresh KEV entry this week (CVE-2025-68686, an information-exposure flaw added 27 July alongside the VeloCloud issue), though the two items above carried the clearer exploitation evidence and India relevance. The throughline is management-plane and gateway software rather than a novel technique: an SD-WAN orchestrator, a firewall manager and a VPN gateway all became attacker footholds once reachable from outside the network they were meant to protect. The Bank of Baroda incident keeps a mailbox-compromise pattern in view for Indian BFSI regardless of how the leak-site data claims are eventually resolved, and the Iranian ICS advisory's expansion to Siemens and Schneider hardware is worth an asset-inventory check even without a named Indian victim, since the exposure runs through shared PLC families rather than India-specific targeting.