Critical Command Injection Vulnerability in Arista VeloCloud Orchestrator Under Active Exploitation

Critical Command Injection Vulnerability in Arista VeloCloud Orchestrator Under Active Exploitation

First seen 28 Jul 2026, 05:51 UTC BleepingcomputerThehackernewsCybersecuritynewsTheregisterGround.News+16 89% similarity 84.3

Article Content

Browse articles
ThreatCluster

A critical command injection vulnerability, CVE-2026-16812, has been discovered in the Arista VeloCloud Orchestrator On-Prem platform, allowing unauthenticated remote attackers to execute arbitrary commands. This flaw, with a CVSS score of 10.0, poses significant risks to organizations using the platform, potentially leading to data breaches and service disruptions. The vulnerability was added to the CISA Known Exploited Vulnerabilities (KEV) catalog on July 27, 2026, confirming active exploitation. Arista has advised affected users to immediately patch their systems or restrict access to trusted networks. The vulnerability affects on-premises deployments, while hosted versions have already been patched. Attackers can exploit the flaw by sending crafted HTTP requests to the orchestrator's web interface. Arista has shared three IP addresses associated with the attacks and recommended monitoring for suspicious activity. The urgency of the situation has prompted CISA to mandate federal agencies to apply patches by July 30, 2026.

Key Points: • CVE-2026-16812 is a critical command injection vulnerability with a CVSS score of 10.0. • The vulnerability allows unauthenticated remote attackers to execute arbitrary commands on affected systems. • Organizations must patch or restrict access to the VeloCloud Orchestrator by July 30, 2026, as mandated by CISA.

ThreatCluster AI How this analysis works

Timeline

2026-02-10
CVE-2025-68686 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-21
Public exploit for CVE-2026-16723 released
A proof-of-concept exploit appeared on GitHub, lowering the barrier for opportunistic attackers.
GitHub
2026-07-27
CVE-2026-16812 added to CISA KEV catalog
CISA confirmed active exploitation of the command injection vulnerability in Arista VeloCloud Orchestrator.
Rescana
2026-07-27
Arista issues security advisory
Arista acknowledged the command injection flaw and its potential impact on on-premises VeloCloud Orchestrator deployments.
Bleepingcomputer
2026-07-28
CISA mandates patching for federal agencies
CISA requires federal civilian executive branch agencies to apply the patch for CVE-2026-16812 by July 30, 2026.
Theregister

Community

Browse all →