Resumen de seguridad: fallas críticas de vCenter de VMware, un Arista Zero-Day activamente explotado y una violación récord de 1,2 millones en atención médica (semana del 31 de julio de 2026)

Weekly threat intelligence briefing: VMware vCenter CVSS 9.8 duo, Arista SD-WAN zero-day, Check Point SmartConsole auth bypass, and MCBS breach.

Resumen de seguridad: fallas críticas de vCenter de VMware, un Arista Zero-Day activamente explotado y una violación récord de 1,2 millones en atención médica (semana del 31 de julio de 2026)

From a dual authentication bypass and root RCE chain in VMware vCenter Server to an in-the-wild Arista SD-WAN zero-day and a 1.26-million-record healthcare breach, here is your executive threat intelligence briefing for the week of July 31, 2026.

Key Stories This Week: VMware vCenter Server Duo: Dual CVSS 9.8 flaws enabling complete virtualization control. Arista VeloCloud SD-WAN: In-the-wild command injection zero-day against orchestrators. Check Point SmartConsole: Active authentication bypass on firewall management servers. MCBS Healthcare Breach: 1.26 million patient records exposed via third-party billing.

1. VMware vCenter Server Auth Bypass & RCE (CVE-2026-59309 & 59310)

Broadcom VMware disclosed critical remote code execution vulnerabilities in vCenter Server enabling unauthenticated attackers to execute commands as root.


2. Arista VeloCloud SD-WAN Command Injection Zero-Day (CVE-2026-16812)

Threat actors actively targeted Arista VeloCloud Orchestrator instances via a pre-auth command injection flaw to hijack software-defined WAN configurations.


3. Check Point SmartConsole Authentication Bypass (CVE-2026-16232)

A critical authentication bypass flaw in Check Point SmartConsole allowed unauthorized rule injection across enterprise firewall perimeters.


4. MCBS Healthcare Medical Billing Breach

Third-party billing vendor MCBS suffered a breach compromising over 1.26 million patient records, including Social Security numbers and clinical diagnostic codes.