< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-07-28T10:13:53+05:30

Arista VeloCloud Orchestrator Command Injection Flaw Exploited by Attackers

A critical command injection vulnerability (CVE-2026-16812, CVSS 10.0) in Arista VeloCloud Orchestrator is actively exploited, enabling remote code execution and potential compromise of enterprise networks. CISA has added the flaw to its KEV catalog, requiring federal agencies to patch by July 30, 2026.

A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild.

The vulnerability, tracked as CVE-2026-16812 (CVSS score: 10.0), is a case of operating system command injection that could pave the way for arbitrary code execution.

"VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue

Read original article

*** END OF TRANSMISSION ***