Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day

Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day
Arista Networks has released patches for a critical OS injection flaw in VeloCloud Orchestrator On-Prem, tracked as CVE-2026-16812, after confirming it was actively exploited as a zero-day. CISA has also added the vulnerability to its KEV catalog, while urging federal agencies to patch it quickly and investigate logs for signs of compromise. #CVE-2026-16812 #VeloCloudOrchestrator #AristaNetworks #CISA #BOD2604

Keypoints

  • Arista Networks fixed a critical OS injection flaw in VeloCloud Orchestrator On-Prem.
  • The vulnerability is tracked as CVE-2026-16812 and has a CVSS score of 10.
  • Arista confirmed the bug was being exploited in the wild as a zero-day.
  • No authentication or special configuration is required, but network access to the web interface is needed.
  • CISA added the flaw to its KEV catalog and ordered rapid patching for federal agencies.

Read More: https://www.securityweek.com/critical-arista-velocloud-orchestrator-vulnerability-exploited-as-zero-day/