Thehackernews Critical Command Injection Vulnerability in Arista VeloCloud Orchestrator Under Active Exploitation
Article Content
- •CVE-2026-16812 is a critical command injection vulnerability with a CVSS score of 10.0.
- •The vulnerability allows unauthenticated remote attackers to execute arbitrary commands on affected systems.
- •Organizations must patch or restrict access to the VeloCloud Orchestrator by July 30, 2026, as mandated by CISA.
A critical command injection vulnerability, CVE-2026-16812, has been discovered in the Arista VeloCloud Orchestrator On-Prem platform, allowing unauthenticated remote attackers to execute arbitrary commands. This flaw, with a CVSS score of 10.0, poses significant risks to organizations using the platform, potentially leading to data breaches and service disruptions. The vulnerability was added to the CISA Known Exploited Vulnerabilities (KEV) catalog on July 27, 2026, confirming active exploitation. Arista has advised affected users to immediately patch their systems or restrict access to trusted networks. The vulnerability affects on-premises deployments, while hosted versions have already been patched. Attackers can exploit the flaw by sending crafted HTTP requests to the orchestrator's web interface. Arista has shared three IP addresses associated with the attacks and recommended monitoring for suspicious activity. The urgency of the situation has prompted CISA to mandate federal agencies to apply patches by July 30, 2026.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (23)
Following this threat?
Track Alibaba and CVE-2025-68686 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Multiple Ransomware Attacks Target Diverse Industries in September 2026 In early September 2026, several ransomware groups executed attacks on various organizations, including Krybit's assault on Reignwood Park Thailand and Arab Maritime Petroleum Transport Company, Everest's attack on VIVOTEK, and Settra's targeting of Golden Neo Life. These incidents involved threats to leak sensitive…
Multiple Organizations Targeted by Krybit Ransomware via FortiBleed Exploit In September 2026, Krybit ransomware claimed multiple victims, including DiamondLease, lasultanahotels.com, EAC Airports, and Ibnsina Trust, all of which had their FortiOS SSL-VPN credentials exposed through the FortiBleed vulnerability (CVE-2022-40684). The attacks leverage the CVE-2022-40684 exploit, which has been…