securityonline.info 8/3/2026, 3:01:47 AM · external

Attackers Exploit VMware, WordPress Zero Days in New CVE Wave

Attackers Exploit VMware, WordPress Zero Days in New CVE Wave
Developing story vulnerability 9 articles tracked
Arista VeloCloud Orchestrator zero‑day command injection exploited (CVE-2026-16812)
CyberSIXT Evidence Panel
CISA KEV Listed in KEV
Patch Patch Available

THE CVE weekly roundup for July 27 to August 2, 2026, reports 2,077 new vulnerabilities, including 273 rated as Critical and 624 as High. Notable vulnerabilities include CVE-2026-16812 (VMware VeloCloud Orchestrator) and CVE-2026-18072 (WordPress ARVE Plugin), both with CVSS scores of 10.0 and confirmed exploitation in the wild. CISA added three entries to its Known Exploited Vulnerabilities list, highlighting four active threats. Recommendations include patching CISA KEV entries, removing compromised WordPress plugins, and upgrading Apache Traffic Server.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline