Security researchers have uncovered dangerous flaws in widely-used network management software that attackers were actively exploiting to break into computer systems. Two major technology companies—Arista and Check Point—discovered that hackers had found ways to take control of their systems without permission.
Arista, a company that makes networking equipment, found a critical vulnerability in its VeloCloud Orchestrator software. This tool helps businesses manage their networks across multiple locations. Hackers discovered a command injection flaw, which means they could inject malicious commands into the system to gain unauthorized control. The vulnerability was particularly dangerous because attackers were already using it in real attacks before Arista even knew about it—making it what security experts call a "zero-day" vulnerability.
Around the same time, Check Point discovered a similar problem in its SmartConsole software. SmartConsole is a tool that network administrators use to manage their security systems. The flaw allowed attackers to bypass normal security protections and gain full administrator access to these systems. This means hackers could control everything on the network, change settings, steal information, or cause serious damage.
Both vulnerabilities represent a serious threat because these tools are used by thousands of businesses and government agencies worldwide. VeloCloud Orchestrator and SmartConsole are popular products that handle critical network operations. When these management tools get compromised, attackers can potentially access sensitive data or disrupt important services.
The fact that attackers were actively exploiting these flaws before the companies discovered them made the situation more urgent. Once the vulnerabilities became public, hackers could have used them to target many more organizations.
Both Arista and Check Point responded quickly by releasing security patches—software updates that fix the problems. The companies strongly encouraged their customers to install these patches immediately. Security experts recommend that any business using these products update their systems right away to protect against attacks.
These discoveries highlight an ongoing challenge in cybersecurity: even major technology companies sometimes miss serious flaws in their products. Attackers are constantly searching for weaknesses they can exploit before companies find them. Organizations that rely on these tools must stay vigilant about applying security updates and monitoring their systems for suspicious activity.