VeloCloud Orchestrator unauthenticated OS command injection, actively exploited (CVE-2026-16812)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2026-16812 is an actively exploited unauthenticated OS command injection flaw in Arista VeloCloud Orchestrator that can expose privileged internal functionality and threaten the orchestrator’s confidentiality, integrity, and availability. The vulnerability affects on-premises VCO deployments and can be reached with only network access to the web interface. Arista says fixed releases are available for impacted trains, while unsupported versions may still need review. CISA has added the CVE to its Known Exploited Vulnerabilities catalog and ordered mitigation for federal civilian agencies by July 30, 2026.
Related Happenings
CISA orders federal mitigation of CVE-2026-16812
Public Sector Action
H score34
First: 28.07.2026 01:49
Last: 28.07.2026 01:49
Sources 1
How related:
CISA has ordered U.S. federal civilian executive branch agencies to mitigate the vulnerability by Thursday, July 30, 2026, as required by Binding Operational Directive 22-01.
About this happening:
CISA ordered U.S. federal civilian executive branch agencies to mitigate CVE-2026-16812 by July 30, 2026, escalating federal response to an actively exploited...
CISA orders federal mitigation of CVE-2026-16812
Public Sector ActionHow related: CISA has ordered U.S. federal civilian executive branch agencies to mitigate the vulnerability by Thursday, July 30, 2026, as required by Binding Operational Directive 22-01.
About this happening: CISA ordered U.S. federal civilian executive branch agencies to mitigate CVE-2026-16812 by July 30, 2026, escalating federal response to an actively exploited...
Timeline
-
28.07.2026 01:49 2 articles · 0h ago
Arista patches actively exploited CVE-2026-16812 in VeloCloud Orchestrator
Initial DisclosureArista disclosed that CVE-2026-16812 is a maximum-severity unauthenticated OS command injection in on-premises VeloCloud Orchestrator that is being actively exploited, allowing remote attackers to reach privileged internal functionality and potentially compromise the confidentiality, integrity, and availability of the orchestrator and the data it manages. Affected releases include VCO 5.2.x before 5.2.3.14, 6.1.x before 6.1.3.4, 6.4.x before 6.4.2.4, and 7.0.x before 7.0.0.1, while fixed versions include 5.2.3.14, 6.1.3.4, 6.4.2.4, and 7.0.0.1 and later. CISA added CVE-2026-16812 to its Known Exploited Vulnerabilities catalog and ordered U.S. federal civilian executive branch agencies to mitigate the vulnerability by Thursday, July 30, 2026.
Show sources
- Arista patches VeloCloud Orchestrator zero-day exploited in attacks — www.bleepingcomputer.com — 28.07.2026 01:49
- Arista patches VeloCloud Orchestrator zero-day exploited in attacks — www.bleepingcomputer.com — 28.07.2026 01:49