Arista patches VeloCloud Orchestrator zero-day exploited in attacks

Arista patches VeloCloud Orchestrator zero-day exploited in attacks
Arista has patched CVE-2026-16812, a maximum-severity unauthenticated OS command injection flaw in on-premises VeloCloud Orchestrator that is being actively exploited. The issue can expose VCO hosts and managed data, and compromised orchestrators may also put VeloCloud Edge devices at risk. #Arista #CVE-2026-16812 #VeloCloudOrchestrator #CISA

Keypoints

  • Arista fixed CVE-2026-16812 in VeloCloud Orchestrator on-premises deployments.
  • The flaw is an unauthenticated OS command injection bug rated 10.0.
  • Attackers can reach privileged internal functionality without credentials.
  • CISA added the vulnerability to its Known Exploited Vulnerabilities catalog.
  • Administrators should patch, restrict access, review logs, and block the listed IPs.

Read More: https://www.bleepingcomputer.com/news/security/arista-patches-velocloud-orchestrator-zero-day-exploited-in-attacks/