Critical CVE-2026-16812 in Arista VeloCloud Orchestrator On-Premises with CVSS 10.0 is being actively exploited by attackers for remote code execution.
Ubiquiti products are at risk from critical flaws that allow unauthenticated attackers to achieve complete system takeover, in some cases directly accessible from the internet.
Lantronix EDS5000 devices are vulnerable to remote code execution via command injection in the login protocol (CVE-2025-67038, CVSS 9.8), and active exploitation is occurring.
Microsoft 365 Copilot contains multiple remotely exploitable vulnerabilities that allow unauthenticated attackers to perform privilege escalation, command injection, and data access.
An unpatched command injection vulnerability in SD-WAN Manager is being actively exploited, requiring immediate measures to close authentication gaps and monitor logs.