RSS Amplifier

Rod’s Blog · Aug 16, 2026

Security Check-in Quick Hits: Critical SAP & Arista Flaws Actively Exploited, Healthcare Billing Breach Hits 1.26M, and n8n RCE PoC Emerges

0
Sign in to vote or save

Rod Trent · Rod’s Blog

SAP’s August Patch Day included a maximum-severity (CVSS 10.0) improper authorization flaw in Commerce Cloud (Data Hub Adapter). An unauthenticated attacker can abuse a default authentication client and craft input to functions lacking sufficient validation, enabling arbitrary code execution and compromise of internal components.

Threat intelligence firm Defused observed the first exploitation attempts hitting honeypots just three days after the patch release—despite no public proof-of-concept. The flaw affects versions including COM_CLOUD 2211 and 2211-JDK21. Successful exploitation risks full instance takeover on a platform used by major retailers and brands for e-commerce operations.

Action items: Apply SAP Security Note 3771065 immediately, restrict internet-facing import/functionality where possible, and monitor for anomalous activity. This is a classic “patch-now, assume-breach” case for any exposed Commerce Cloud deployment.

Arista’s on-premises VeloCloud Orchestrator (VCO)—the management plane for SD-WAN edges—contains an unauthenticated OS command injection vulnerability scored CVSS 10.0. Attackers with network access to the web interface can reach privileged internal functionality never intended for external exposure and execute arbitrary commands, potentially controlling network routing and every branch the orchestrator provisions.

The issue affects multiple release trains (5.2.x prior to 5.2.3.14, 6.1.x prior to 6.1.3.4, 6.4.x prior to 6.4.2.4, and 7.0.x prior to 7.0.0.1). Hosted/cloud versions were patched in advance; on-prem is the exposure. Active exploitation has been confirmed, and the interface is exposed by default with no configuration toggle to fully disable the risk.

Action items: Upgrade immediately to the fixed releases. Restrict management interface access to trusted networks as a temporary control, hunt for signs of command execution or unexpected configuration changes, and treat any internet-exposed VCO as high priority.

Medical Computer Business Services (MCBS), a firm handling medical billing, suffered a breach that exposed personal and health details of approximately 1.26 million people. Reporting indicates the incident involved credential theft and data exposure in the healthcare billing sector; the breach itself appears to have occurred earlier (2025) but was disclosed/reported in the current window.

No public confirmation of ransomware deployment or active ongoing exploitation was highlighted in initial coverage, but the volume and sensitivity of the data (personal + health information) make this a significant privacy and identity-theft risk event for affected individuals.

Action items: If you or your organization interact with MCBS or similar billing providers, monitor for notification letters, place fraud alerts/credit freezes as appropriate, and watch for phishing that leverages the exposed data. Healthcare-adjacent supply-chain breaches continue to be a high-impact vector.

A critical remote code execution vulnerability in the popular open-source n8n workflow automation platform (affecting expression evaluation / sandbox isolation) has seen proof-of-concept exploit code released. The flaw enables authenticated (and in some related variants, broader) attackers to escape intended execution contexts and run arbitrary code on the host, risking full instance compromise, secret theft, and lateral movement.

Tens of thousands of instances have been reported as potentially exposed in past scans of similar n8n issues. Self-hosted deployments with workflow editing enabled are particularly at risk.

Action items: Upgrade to the latest patched n8n releases immediately. Limit who can create or edit workflows, review exposed webhook/form endpoints, and treat any internet-facing n8n instance as high priority for hardening.

These four items illustrate the current pressure points: edge/management-plane appliances and automation platforms remaining high-value targets for unauthenticated or low-friction RCE, combined with steady healthcare data exposure. Prioritize internet-facing SD-WAN orchestrators, e-commerce platforms, workflow tools, and third-party billing processors in your next patch and monitoring cycle.

Stay patched, least-privilege everything, and verify your exposure surface. More as the picture develops.

Read the original on rodtrent.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.