Arista VeloCloud Orchestrator Flaw Rated CVSS 10.0 Actively Exploited in Wild
Arista disclosed CVE-2026-16812, a maximum-severity OS command injection vulnerability in on-premises VeloCloud Orchestrator (VCO), confirming it was already under active exploitation when the advisory was published on July 27, 2026. The flaw allows unauthenticated remote attackers to access privileged internal functionality on the VCO host, potentially extending control to all VeloCloud Edge devices managed by the orchestrator. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog and set a July 30, 2026 remediation deadline for Federal Civilian Executive Branch agencies. Arista has released patches across four affected release branches — versions 5.2.3.14, 6.1.3.4, 6.4.2.4, and 7.0.0.1 — while its hosted and dedicated VCO instances were already remediated in advance. Organizations unable to patch immediately are advised to block three attacker-attributed IP addresses and restrict VCO web interface access to trusted administrative networks only.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in