Arista patches critical VeloCloud Orchestrator zero-day under active exploitation
Arista has released patches for CVE-2026-16812, a CVSS 10.0 unauthenticated OS command injection vulnerability affecting on-premises VeloCloud Orchestrator (VCO) installations. The flaw allows an external attacker to send a crafted request to the VCO web interface without any credentials, reaching internal-only functions and executing arbitrary commands on the host. Attackers can steal configurations, credentials, certificates, and database contents, and may further compromise Edge devices managed by the affected VCO, extending risk across the entire SD-WAN. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on July 27, 2026, confirming active exploitation in the wild. Arista advises administrators to apply fixed versions immediately and, if compromise is suspected, to rotate all credentials, certificates, and keys and validate the integrity of managed Edge devices.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in