A maximum-severity command injection vulnerability in on-premises versions of Arista VeloCloud Orchestrator (VCO) is being actively exploited. Tracked as CVE-2026-16812 with a…
Security firms ThreatBook and Imperva report active exploitation of a critical remote code execution vulnerability in Alibaba's Fastjson 1.x JSON library for…
A critical unpatched vulnerability in Alibaba Fastjson library (versions 1.2.68-1.2.83) with CVSS 9.0, allowing remote code execution without user interaction. Developers urged…