This digest compiles five vendor security advisories published by the Canadian Centre for Cyber Security on 2026-07-28, spanning Apache Thrift, Arista VeloCloud Orchestrator, JetBrains TeamCity, Apple's OS/software ecosystem, and Vercel's Next.js framework. The most urgent item is CVE-2026-16812 affecting Arista VeloCloud Orchestrator On-Prem, which CISA added to its Known Exploited Vulnerabilities catalog on July 27, 2026, confirming active exploitation. The remaining advisories describe vendor-disclosed vulnerabilities (decompression bombs, integer overflow, out-of-bounds read, and unspecified fixed issues) without confirmed in-the-wild exploitation at the time of publication.
Cyber Centre Advisory
1 post
Cyber Centre Daily Advisory Digest — 2026-07-28 (5 advisories)