Find notable cyber news and cases, enriched with sources, timelines, and signals.

CISA orders federal mitigation of CVE-2026-16812

Public Sector Action
First reported
Last updated
Happening score
H score 34
1 unique sources, 1 articles

Summary

Hide ▲

CISA ordered U.S. federal civilian executive branch agencies to mitigate CVE-2026-16812 by July 30, 2026, escalating federal response to an actively exploited zero-day in Arista VeloCloud Orchestrator. The directive adds urgency to remediation because the flaw can let remote attackers reach privileged internal functionality and compromise managed systems and data.

Related Happenings

VeloCloud Orchestrator unauthenticated OS command injection, actively exploited (CVE-2026-16812)

Vulnerability
H score48 First: 28.07.2026 01:49 Last: 28.07.2026 01:49 Sources 1

How related: The vulnerability, tracked as CVE-2026-16812, is an unauthenticated OS command injection flaw with severity scores of 10.0, the maximum score that can be given to flaws.

About this happening: CVE-2026-16812 is an actively exploited unauthenticated OS command injection flaw in Arista VeloCloud Orchestrator that can expose privileged internal functionality an...

Arista VeloCloud Orchestrator security update for CVE-2026-16812

Security Patch Release
H score53 First: 28.07.2026 01:49 Last: 28.07.2026 01:49 Sources 1

How related: The company says the flaw is fixed in VCO versions 5.2.3.14, 6.1.3.4, and 6.4.2.4 and later.

About this happening: Arista released fixes for on-premises VeloCloud Orchestrator after CVE-2026-16812 was confirmed actively exploited, exposing SD-WAN management systems to remote co...

CISA BOD 26-04 prioritizes vulnerability remediation for federal civilian agencies

Public Sector Action
H score27 First: 10.06.2026 15:00 Last: 10.06.2026 15:00 Sources 1

About this happening: CISA issued Binding Operational Directive 26-04 to require federal civilian agencies to prioritize vulnerability remediation using Asset Exposure, KEV Status,...

Cisco security patch release for CVE-2026-20188

Security Patch Release
H score35 First: 06.05.2026 21:06 Last: 06.05.2026 21:06 Sources 1

About this happening: Cisco released security updates for CVE-2026-20188, a high-severity DoS vulnerability in Crosswork Network Controller (CNC) and Network Services Orchestrator (NS...

Federal civilian executive branch agency hit by network compromise

Incident
H score21 First: 24.04.2026 23:34 Last: 24.04.2026 23:34 Sources 1

About this happening: A federal civilian executive branch agency was compromised in an early September 2025 intrusion that left attackers with persistent access on Cisco Firepower and Sec...

Timeline

  1. 28.07.2026 01:49 1 articles · 0h ago

    Arista patches actively exploited VeloCloud Orchestrator command injection

    Initial Disclosure

    Arista patched CVE-2026-16812 in on-premises VeloCloud Orchestrator, an unauthenticated OS command injection rated 10.0, and said the flaw was already being actively exploited to reach privileged internal functionality and could compromise the orchestrator and the data it manages. The affected releases were VCO 5.2.x before 5.2.3.14, 6.1.x before 6.1.3.4, 6.4.x before 6.4.2.4, and 7.0.x before 7.0.0.1.

    Show sources
  2. 28.07.2026 01:49 2 articles · 0h ago

    CISA orders federal mitigation of CVE-2026-16812

    Legal Policy Action Update

    CISA added CVE-2026-16812 to the Known Exploited Vulnerabilities catalog and ordered U.S. federal civilian executive branch agencies to mitigate the flaw by Thursday, July 30, 2026, under Binding Operational Directive 22-01. The federal directive treats the vulnerability as actively exploited and requires remediation on the public-sector timetable.

    Show sources