MSP Threat Radar Weekly Briefing — Week of 2026-07-27

This week’s briefing tracks 12 recent watch items across 4 vendors, with emphasis on active service incidents and high-priority operational issues.

Full briefing

Markdown rendered

MSP Threat Radar Weekly Briefing — Week of 2026-07-27

This week’s briefing tracks 12 recent watch items across 4 vendors, with emphasis on active service incidents and high-priority operational issues.

Top items

Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability

Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Due date: 2026-08-01.

Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Due date: 2026-08-10.

velocloud orchestrator vulnerability (CVE-2026-16812)

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. This functionality was intended to be for internal use only and is not intended to be remotely accessible. Hosted and Dedicated versions of VCO have already been patched in advance of this notice going out. This issue was discovered externally and is known to be actively exploited.

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Review affected assets, prioritize patch validation, and map remediation against managed client inventory.

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability (CVE-2026-66321)

Information published.

Customer action is required. Review the Security Update Guide entry, confirm affected Microsoft products, and prioritize patch validation or mitigation.

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability (CVE-2026-66315)

Information published.

Customer action is required. Review the Security Update Guide entry, confirm affected Microsoft products, and prioritize patch validation or mitigation.

Briefing detail

About this briefing

Published

August 2, 2026

Read time

3 min read

Highlights

5 key items

This week's highlights

  • Cisco: Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
  • Fortinet: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
  • Arista: velocloud orchestrator vulnerability (CVE-2026-16812)
  • Microsoft: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability (CVE-2026-66321)
  • Microsoft: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability (CVE-2026-66315)