Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
Overview
A serious security flaw has been discovered in the on-premises version of Arista's VeloCloud Orchestrator, identified as CVE-2026-16812, which carries a maximum CVSS score of 10.0. This vulnerability is a command injection issue that could allow attackers to execute arbitrary code on affected systems. As it is actively being exploited in the wild, organizations using this software need to be particularly vigilant. The flaw affects on-premises deployments of the VeloCloud Orchestrator, which is used for managing network services. The implications of this vulnerability are significant, as it could lead to unauthorized access and control over critical network functions if left unaddressed.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Arista VeloCloud Orchestrator (VCO) on-premises versions
- Action Required: Organizations using VeloCloud Orchestrator should immediately apply any available security patches from Arista and review their system configurations to mitigate potential exploitation.
- Timeline: Newly disclosed
Original Article Summary
A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-16812 (CVSS score: 10.0), is a case of operating system command injection that could pave the way for arbitrary code execution. "VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue
Impact
Arista VeloCloud Orchestrator (VCO) on-premises versions
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Organizations using VeloCloud Orchestrator should immediately apply any available security patches from Arista and review their system configurations to mitigate potential exploitation. It is also recommended to monitor network traffic for any suspicious activity related to this vulnerability.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to CVE, Exploit, Vulnerability, and 2 more.