Thehackernews
Critical Command Injection Vulnerability in Arista VeloCloud Orchestrator Under Active Exploitation
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A critical command injection vulnerability, CVE-2026-16812, has been discovered in the Arista VeloCloud Orchestrator On-Prem platform, allowing unauthenticated remote attackers to execute arbitrary commands. This flaw, with a CVSS score of 10.0, poses significant risks to organizations using the platform, potentially leading to data breaches and service disruptions. The vulnerability was added to the CISA Known Exploited Vulnerabilities (KEV) catalog on July 27, 2026, confirming active exploitation. Arista has advised affected users to immediately patch their systems or restrict access to trusted networks. The vulnerability affects on-premises deployments, while hosted versions have already been patched. Attackers can exploit the flaw by sending crafted HTTP requests to the orchestrator's web interface. Arista has shared three IP addresses associated with the attacks and recommended monitoring for suspicious activity. The urgency of the situation has prompted CISA to mandate federal agencies to apply patches by July 30, 2026.
Key Points: • CVE-2026-16812 is a critical command injection vulnerability with a CVSS score of 10.0. • The vulnerability allows unauthenticated remote attackers to execute arbitrary commands on affected systems. • Organizations must patch or restrict access to the VeloCloud Orchestrator by July 30, 2026, as mandated by CISA.