Utopia Tech
▸ Engineering & Strategy Journal

Field notes from the edge.

What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.

Attackers Exploit Arista VeloCloud Orchestrator Command Injection FlawAI
Security

Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw

A critical command injection vulnerability (CVE-2026-16812) with a maximum CVSS score of 10.0 has been discovered in on-premises versions of Arista VeloCloud Orchestrator and is being actively exploited. The flaw allows attackers to execute arbitrary code through operating system command injection, posing severe security risks to affected enterprise deployments.

UTUtopia Tech·1 min
Cisco Releases Security Updates for Actively Exploited SD-WAN Manager FlawAI
Security

Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw

Cisco has issued security patches for CVE-2026-20262, a medium-severity vulnerability in Catalyst SD-WAN Manager (formerly SD-WAN vManage) that is being actively exploited. The flaw, with a CVSS score of 6.5, affects the web UI and allows authenticated remote attackers to create files on the system. Organizations using Cisco SD-WAN solutions should prioritize applying these updates immediately giv

UTUtopia Tech·1 min
Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch AvailableAI
Security

Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available

Cisco has issued a warning about active exploitation of CVE-2026-20245, a high-severity vulnerability (CVSS 7.8) affecting Catalyst SD-WAN Manager across multiple deployment models. The flaw impacts on-premises, cloud-managed, and government FedRAMP deployments, with no patch currently available, creating urgent security concerns for enterprise SD-WAN infrastructure.

UTUtopia Tech·1 min
Cisco Catalyst SD-WAN Controller Auth Bypass Actively Exploited to Gain Admin AccessAI
Security

Cisco Catalyst SD-WAN Controller Auth Bypass Actively Exploited to Gain Admin Access

Cisco has issued critical security updates for a maximum-severity authentication bypass vulnerability (CVE-2026-20182, CVSS 10.0) in Catalyst SD-WAN Controller and Manager products. The flaw, affecting peering authentication mechanisms, has been actively exploited in limited attacks to gain unauthorized administrative access. Organizations using these SD-WAN solutions should prioritize immediate p

UTUtopia Tech·1 min
Skip to main content