Arista VeloCloud Orchestrator security update for CVE-2026-16812
Security Patch Release
Summary
Hide ▲
Show ▼
Arista released fixes for on-premises VeloCloud Orchestrator after CVE-2026-16812 was confirmed actively exploited, exposing SD-WAN management systems to remote compromise. The flaw is a maximum-severity 10.0 unauthenticated OS command injection that can reach privileged internal functionality. Affected customers must move to 5.2.3.14, 6.1.3.4, 6.4.2.4, or 7.0.0.1 and later.
Related Happenings
CISA orders federal mitigation of CVE-2026-16812
Public Sector Action
H score34
First: 28.07.2026 01:49
Last: 28.07.2026 01:49
Sources 1
How related:
CISA has ordered U.S. federal civilian executive branch agencies to mitigate the vulnerability by Thursday, July 30, 2026, as required by Binding Operational Directive 22-01.
About this happening:
CISA ordered U.S. federal civilian executive branch agencies to mitigate CVE-2026-16812 by July 30, 2026, escalating federal response to an actively exploited...
CISA orders federal mitigation of CVE-2026-16812
Public Sector ActionHow related: CISA has ordered U.S. federal civilian executive branch agencies to mitigate the vulnerability by Thursday, July 30, 2026, as required by Binding Operational Directive 22-01.
About this happening: CISA ordered U.S. federal civilian executive branch agencies to mitigate CVE-2026-16812 by July 30, 2026, escalating federal response to an actively exploited...
RabbitMQ maintainers security patch release for CVE-2026-57219
Security Patch Release
H score29
First: 14.07.2026 16:48
Last: 14.07.2026 16:48
Sources 1
About this happening:
RabbitMQ maintainers released fixed versions for multiple supported release lines, closing two access-control flaws that could expose OAuth client secrets and cross-te...
RabbitMQ maintainers security patch release for CVE-2026-57219
Security Patch ReleaseAbout this happening: RabbitMQ maintainers released fixed versions for multiple supported release lines, closing two access-control flaws that could expose OAuth client secrets and cross-te...
Cisco security patch release for CVE-2026-20262
Security Patch Release
H score47
First: 15.06.2026 20:12
Last: 15.06.2026 20:12
Sources 1
About this happening:
Cisco released security updates for CVE-2026-20262 in Catalyst SD-WAN Manager, covering multiple release trains after the zero-day was exploited to reach root pr...
Cisco security patch release for CVE-2026-20262
Security Patch ReleaseAbout this happening: Cisco released security updates for CVE-2026-20262 in Catalyst SD-WAN Manager, covering multiple release trains after the zero-day was exploited to reach root pr...
Cisco Secure Workload REST API patch release (CVE-2026-20223)
Security Patch Release
H score55
First: 22.05.2026 08:36
Last: 22.05.2026 08:36
Sources 1
About this happening:
Cisco patched CVE-2026-20223, a CVSS 10.0 Secure Workload REST API flaw that could expose sensitive data and allow configuration changes across tenant boundaries. The upda...
Cisco Secure Workload REST API patch release (CVE-2026-20223)
Security Patch ReleaseAbout this happening: Cisco patched CVE-2026-20223, a CVSS 10.0 Secure Workload REST API flaw that could expose sensitive data and allow configuration changes across tenant boundaries. The upda...
Cisco security patch release for CVE-2026-20184
Security Patch Release
H score44
First: 16.04.2026 14:27
Last: 16.04.2026 14:27
Sources 1
About this happening:
Cisco released patches for four critical flaws affecting Identity Services Engine (ISE), ISE-PIC, and Webex Services, closing paths to arbitrary code executi...
Cisco security patch release for CVE-2026-20184
Security Patch ReleaseAbout this happening: Cisco released patches for four critical flaws affecting Identity Services Engine (ISE), ISE-PIC, and Webex Services, closing paths to arbitrary code executi...
Timeline
-
28.07.2026 01:49 2 articles · 0h ago
Arista patches actively exploited VeloCloud Orchestrator command injection flaw
Initial DisclosureArista patched CVE-2026-16812, an unauthenticated OS command injection flaw in on-premises VeloCloud Orchestrator, after confirming it is being actively exploited; successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and the data it manages. CISA also added the CVE to its Known Exploited Vulnerabilities catalog and directed U.S. federal civilian executive branch agencies to mitigate it by Thursday, July 30, 2026.
Show sources
- Arista patches VeloCloud Orchestrator zero-day exploited in attacks — www.bleepingcomputer.com — 28.07.2026 01:49
- Arista patches VeloCloud Orchestrator zero-day exploited in attacks — www.bleepingcomputer.com — 28.07.2026 01:49