Arista has patched CVE-2026-16812, a maximum-severity unauthenticated OS command injection flaw in on-premises VeloCloud Orchestrator that is being actively exploited. The issue can expose VCO hosts and managed data, and compromised orchestrators may also put VeloCloud Edge devices at risk. #Arista #CVE-2026-16812 #VeloCloudOrchestrator #CISA
Keypoints
- Arista fixed CVE-2026-16812 in VeloCloud Orchestrator on-premises deployments.
- The flaw is an unauthenticated OS command injection bug rated 10.0.
- Attackers can reach privileged internal functionality without credentials.
- CISA added the vulnerability to its Known Exploited Vulnerabilities catalog.
- Administrators should patch, restrict access, review logs, and block the listed IPs.