CISA orders federal mitigation of CVE-2026-16812
Public Sector Action
Summary
Hide ▲
Show ▼
CISA ordered U.S. federal civilian executive branch agencies to mitigate CVE-2026-16812 by July 30, 2026, escalating federal response to an actively exploited zero-day in Arista VeloCloud Orchestrator. The directive adds urgency to remediation because the flaw can let remote attackers reach privileged internal functionality and compromise managed systems and data.
Related Happenings
VeloCloud Orchestrator unauthenticated OS command injection, actively exploited (CVE-2026-16812)
Vulnerability
H score48
First: 28.07.2026 01:49
Last: 28.07.2026 01:49
Sources 1
How related:
The vulnerability, tracked as CVE-2026-16812, is an unauthenticated OS command injection flaw with severity scores of 10.0, the maximum score that can be given to flaws.
About this happening:
CVE-2026-16812 is an actively exploited unauthenticated OS command injection flaw in Arista VeloCloud Orchestrator that can expose privileged internal functionality an...
VeloCloud Orchestrator unauthenticated OS command injection, actively exploited (CVE-2026-16812)
VulnerabilityHow related: The vulnerability, tracked as CVE-2026-16812, is an unauthenticated OS command injection flaw with severity scores of 10.0, the maximum score that can be given to flaws.
About this happening: CVE-2026-16812 is an actively exploited unauthenticated OS command injection flaw in Arista VeloCloud Orchestrator that can expose privileged internal functionality an...
Arista VeloCloud Orchestrator security update for CVE-2026-16812
Security Patch Release
H score53
First: 28.07.2026 01:49
Last: 28.07.2026 01:49
Sources 1
How related:
The company says the flaw is fixed in VCO versions 5.2.3.14, 6.1.3.4, and 6.4.2.4 and later.
About this happening:
Arista released fixes for on-premises VeloCloud Orchestrator after CVE-2026-16812 was confirmed actively exploited, exposing SD-WAN management systems to remote co...
Arista VeloCloud Orchestrator security update for CVE-2026-16812
Security Patch ReleaseHow related: The company says the flaw is fixed in VCO versions 5.2.3.14, 6.1.3.4, and 6.4.2.4 and later.
About this happening: Arista released fixes for on-premises VeloCloud Orchestrator after CVE-2026-16812 was confirmed actively exploited, exposing SD-WAN management systems to remote co...
CISA BOD 26-04 prioritizes vulnerability remediation for federal civilian agencies
Public Sector Action
H score27
First: 10.06.2026 15:00
Last: 10.06.2026 15:00
Sources 1
About this happening:
CISA issued Binding Operational Directive 26-04 to require federal civilian agencies to prioritize vulnerability remediation using Asset Exposure, KEV Status,...
CISA BOD 26-04 prioritizes vulnerability remediation for federal civilian agencies
Public Sector ActionAbout this happening: CISA issued Binding Operational Directive 26-04 to require federal civilian agencies to prioritize vulnerability remediation using Asset Exposure, KEV Status,...
Cisco security patch release for CVE-2026-20188
Security Patch Release
H score35
First: 06.05.2026 21:06
Last: 06.05.2026 21:06
Sources 1
About this happening:
Cisco released security updates for CVE-2026-20188, a high-severity DoS vulnerability in Crosswork Network Controller (CNC) and Network Services Orchestrator (NS...
Cisco security patch release for CVE-2026-20188
Security Patch ReleaseAbout this happening: Cisco released security updates for CVE-2026-20188, a high-severity DoS vulnerability in Crosswork Network Controller (CNC) and Network Services Orchestrator (NS...
Federal civilian executive branch agency hit by network compromise
Incident
H score21
First: 24.04.2026 23:34
Last: 24.04.2026 23:34
Sources 1
About this happening:
A federal civilian executive branch agency was compromised in an early September 2025 intrusion that left attackers with persistent access on Cisco Firepower and Sec...
Federal civilian executive branch agency hit by network compromise
IncidentAbout this happening: A federal civilian executive branch agency was compromised in an early September 2025 intrusion that left attackers with persistent access on Cisco Firepower and Sec...
Timeline
-
28.07.2026 01:49 1 articles · 0h ago
Arista patches actively exploited VeloCloud Orchestrator command injection
Initial DisclosureArista patched CVE-2026-16812 in on-premises VeloCloud Orchestrator, an unauthenticated OS command injection rated 10.0, and said the flaw was already being actively exploited to reach privileged internal functionality and could compromise the orchestrator and the data it manages. The affected releases were VCO 5.2.x before 5.2.3.14, 6.1.x before 6.1.3.4, 6.4.x before 6.4.2.4, and 7.0.x before 7.0.0.1.
Show sources
- Arista patches VeloCloud Orchestrator zero-day exploited in attacks — www.bleepingcomputer.com — 28.07.2026 01:49
-
28.07.2026 01:49 2 articles · 0h ago
CISA orders federal mitigation of CVE-2026-16812
Legal Policy Action UpdateCISA added CVE-2026-16812 to the Known Exploited Vulnerabilities catalog and ordered U.S. federal civilian executive branch agencies to mitigate the flaw by Thursday, July 30, 2026, under Binding Operational Directive 22-01. The federal directive treats the vulnerability as actively exploited and requires remediation on the public-sector timetable.
Show sources
- Arista patches VeloCloud Orchestrator zero-day exploited in attacks — www.bleepingcomputer.com — 28.07.2026 01:49
- Arista patches VeloCloud Orchestrator zero-day exploited in attacks — www.bleepingcomputer.com — 28.07.2026 01:49