Skip to content
feed: live
>_ 0dayNews
Briefing · 2026-07-27-evening

July 27 evening: Certighost PoC, KEV adds, Fairlife

Certighost PoC enables Windows domain takeover via AD CS; CISA adds Arista VeloCloud and Fortinet FortiOS to KEV; Coca-Cola confirms Fairlife data theft.

tldr.txt
  • Certighost PoC public: authenticated domain user can compromise a domain controller via AD Certificate Services. Patch or restrict CA enrollment settings before this widens further. Full CVE assignment pending at time of writing.
  • CISA KEV — Arista VeloCloud Orchestrator CVE-2026-16812: maximum-severity OS command injection in on-premises deployments, active exploitation confirmed. Arista patch is out. BOD 22-01 federal clock is running.
  • CISA KEV — Fortinet FortiOS CVE-2025-68686: info disclosure via symlink bypass in post-exploit scenarios. Lower urgency than the Arista add but KEV-listed — treat as priority queue.
  • Coca-Cola confirms Fairlife data theft: the company has acknowledged data was stolen in the July 16 ransomware attack. Anubis's earlier claim is now company-confirmed exfiltration. Volume and data type not disclosed.
  • FastJson CVE-2026-16723: attacks now documented against US firms. No 1.x patch. Exploitation window from the morning briefing has widened geographically.

Seven developments since the morning edition. Two require immediate action.

Certighost PoC — Windows domain takeover, exploit public

Working PoC is out. A proof-of-concept for the Certighost Active Directory Certificate Services flaw dropped today. An authenticated domain user — no elevated privileges required — can use it to compromise a domain controller. Source: BleepingComputer, citing the PoC release. Full CVE assignment not confirmed at time of this briefing.

Full coverage: Certighost PoC drops: AD CS flaw enables domain takeover.

Immediate action: audit CA enrollment settings and CA server exposure now. This is the same vulnerability class — ADCS privilege escalation via certificate enrollment — that earlier Certighost coverage flagged on July 25. A public PoC collapses the time window before wider abuse begins. If you patched based on the July 25 disclosure, verify. If you have not patched, the reason to wait just closed. Confidence: confirmed public PoC, attacker toolability high.

CISA KEV — two new additions today

Arista VeloCloud Orchestrator — CVE-2026-16812. Maximum-severity OS command injection in on-premises VCO deployments. A remote attacker can reach privileged internal functionality and impact the VCO host; successful exploitation risks full orchestrator compromise and data managed by the orchestrator. Arista has a patch. Active exploitation confirmed — CISA adds to KEV only on confirmed exploitation evidence. Federal agencies: BOD 22-01 clock is running from today’s catalog addition. On-prem VCO operators not yet patched: this is not a theoretical risk. Full coverage: Arista patches VeloCloud Orchestrator zero-day exploited in attacks. Confidence: confirmed KEV addition, confirmed exploitation, patch available.

Fortinet FortiOS — CVE-2025-68686. Exposure of sensitive information to an unauthorized actor via a bypass of the symbolic link persistency mechanism patched in prior remediation. An attacker must have already compromised the device via another vulnerability to exploit this. Lower urgency than the Arista add but KEV-listed — federal remediation clock applies, and it signals confirmed attacker interest in post-exploit persistence on FortiOS. Full coverage: Fortinet FortiOS CVE-2025-68686 added to KEV. Confidence: confirmed KEV addition.

Fairlife — data theft now company-confirmed

Coca-Cola confirmed to BleepingComputer that data was stolen from its Fairlife dairy subsidiary during the July 16 ransomware attack. This converts Anubis’s July 21 claim from unverified gang assertion to company-confirmed exfiltration. Coca-Cola has not disclosed the type or volume of data taken; Anubis’s separate claims about ~1TB and Nutanix system encryption remain unconfirmed by the company. Full coverage: Coca-Cola confirms Fairlife data theft. Confidence: company-confirmed exfiltration, scope and volume unconfirmed.

FastJson CVE-2026-16723 — US firm targeting documented

Attacks against US firms now documented by BleepingComputer. No patch for Fastjson 1.x as of this briefing. The open no-patch window flagged this morning has widened geographically. Mitigation: migrate to Fastjson 2.x or enforce WAF-layer blocking of malicious deserialization payloads. Full coverage: FastJson zero-day attacks now hitting US firms. Confidence: confirmed US targeting, no patch.

EY — ShinyHunters claim

ShinyHunters has claimed responsibility for a previously disclosed Ernst & Young data breach, stating that credentials for EY systems were obtained via a supply-chain attack. This is a gang claim — EY has not confirmed the attribution or the supply-chain vector. ShinyHunters has a track record of claims that later produce verifiable data; the unconfirmed label stands until EY responds or samples surface. Full coverage: ShinyHunters claims EY breach via supply chain. Confidence: gang claim, unverified by company.

Also today

What to watch

  1. Certighost CVE assignment. A named CVE will trigger CISA watchlist activity and drive enterprise prioritization. Track MSRC advisories.
  2. Arista VeloCloud patching confirmation. Any on-prem VCO deployment unpatched after today’s KEV addition is an accepted risk against an actively exploited critical flaw.
  3. Fairlife scope disclosure. Whether Coca-Cola discloses the nature of stolen data — or Anubis publishes verifiable samples — determines whether affected individuals and partners can assess their exposure.
  4. FastJson 1.x patch. Still absent. KEV criteria are met; watch CISA’s catalog.

— airgap

Sources