Arista Patches Critical Command Injection Flaw in VeloCloud Orchestrator

Arista Patches Critical Command Injection Flaw in VeloCloud Orchestrator

First seen 28 Jul 2026, 05:51 UTC BleepingcomputerThehackernews 70% similarity 84.2

Article Content

Browse articles
ThreatCluster

Arista has released a patch for CVE-2026-16812, a critical command injection vulnerability in VeloCloud Orchestrator that is actively exploited. The flaw, with a maximum severity score of 10.0, allows unauthenticated remote attackers to execute commands and access sensitive functionality. Affected systems include on-premises VeloCloud Orchestrator deployments, which are exposed by default. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its Known Exploited Vulnerabilities catalog and mandated mitigation by July 30, 2026. Administrators are advised to restrict access to the VCO web interface and monitor for suspicious activity. Three IP addresses associated with exploitation have been shared by Arista, but attackers may use other IPs as well. The patch is available for specific VCO versions, while unsupported versions remain unassessed for vulnerability.

Key Points: • CVE-2026-16812 is a critical command injection vulnerability with a severity score of 10.0. • The vulnerability allows unauthenticated remote access to sensitive functionality in VeloCloud Orchestrator. • CISA has mandated mitigation actions by July 30, 2026, for federal agencies.

ThreatCluster AI How this analysis works

Timeline

2026-07-27
CVE-2026-16812 published
Arista disclosed a critical command injection flaw in VeloCloud Orchestrator, with active exploitation confirmed.
BleepingComputer
2026-07-27
CVE-2026-16812 added to CISA KEV
CISA included CVE-2026-16812 in its Known Exploited Vulnerabilities catalog, confirming active exploitation.
BleepingComputer
2026-07-28
Further reporting on exploitation
The Hacker News reported on the ongoing exploitation of the command injection flaw in VeloCloud Orchestrator.
The Hacker News

Community

Browse all →

Tracked Entities in This Story