Thehackernews
Arista Patches Critical Command Injection Flaw in VeloCloud Orchestrator
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Arista has released a patch for CVE-2026-16812, a critical command injection vulnerability in VeloCloud Orchestrator that is actively exploited. The flaw, with a maximum severity score of 10.0, allows unauthenticated remote attackers to execute commands and access sensitive functionality. Affected systems include on-premises VeloCloud Orchestrator deployments, which are exposed by default. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its Known Exploited Vulnerabilities catalog and mandated mitigation by July 30, 2026. Administrators are advised to restrict access to the VCO web interface and monitor for suspicious activity. Three IP addresses associated with exploitation have been shared by Arista, but attackers may use other IPs as well. The patch is available for specific VCO versions, while unsupported versions remain unassessed for vulnerability.
Key Points: • CVE-2026-16812 is a critical command injection vulnerability with a severity score of 10.0. • The vulnerability allows unauthenticated remote access to sensitive functionality in VeloCloud Orchestrator. • CISA has mandated mitigation actions by July 30, 2026, for federal agencies.