
Hardware
Arista's SD-WAN box has a bug so bad hackers don't even need a password
CVE-2026-16812 scores a perfect 10, needs zero credentials, and CISA is already watching it get used against real networks.
Ravi Malhotra · Aug 3 · 7 min
3 articles · newest first

CVE-2026-16812 scores a perfect 10, needs zero credentials, and CISA is already watching it get used against real networks.
Ravi Malhotra · Aug 3 · 7 min

CVE-2026-25089 is an unauthenticated command-injection flaw in FortiSandbox, the security appliance meant to catch malware. It's on CISA's exploited list. The tool that inspects threats has become one.
Priya Nair · Jul 28 · 9 min

CVE-2026-10520 scores a maximum 10.0 — the rarest severity rating there is. No login, one network request, and an attacker owns the box as root. It's on CISA's exploited list, with public exploit code and confirmed backdoors.
Priya Nair · Jul 28 · 7 min