Find notable cyber news and cases, enriched with sources, timelines, and signals.

VeloCloud Orchestrator unauthenticated OS command injection, actively exploited (CVE-2026-16812)

Vulnerability
First reported
Last updated
Happening score
H score 48
1 unique sources, 1 articles

Summary

Hide ▲

CVE-2026-16812 is an actively exploited unauthenticated OS command injection flaw in Arista VeloCloud Orchestrator that can expose privileged internal functionality and threaten the orchestrator’s confidentiality, integrity, and availability. The vulnerability affects on-premises VCO deployments and can be reached with only network access to the web interface. Arista says fixed releases are available for impacted trains, while unsupported versions may still need review. CISA has added the CVE to its Known Exploited Vulnerabilities catalog and ordered mitigation for federal civilian agencies by July 30, 2026.

Related Happenings

CISA orders federal mitigation of CVE-2026-16812

Public Sector Action
H score34 First: 28.07.2026 01:49 Last: 28.07.2026 01:49 Sources 1

How related: CISA has ordered U.S. federal civilian executive branch agencies to mitigate the vulnerability by Thursday, July 30, 2026, as required by Binding Operational Directive 22-01.

About this happening: CISA ordered U.S. federal civilian executive branch agencies to mitigate CVE-2026-16812 by July 30, 2026, escalating federal response to an actively exploited...

Timeline

  1. 28.07.2026 01:49 2 articles · 0h ago

    Arista patches actively exploited CVE-2026-16812 in VeloCloud Orchestrator

    Initial Disclosure

    Arista disclosed that CVE-2026-16812 is a maximum-severity unauthenticated OS command injection in on-premises VeloCloud Orchestrator that is being actively exploited, allowing remote attackers to reach privileged internal functionality and potentially compromise the confidentiality, integrity, and availability of the orchestrator and the data it manages. Affected releases include VCO 5.2.x before 5.2.3.14, 6.1.x before 6.1.3.4, 6.4.x before 6.4.2.4, and 7.0.x before 7.0.0.1, while fixed versions include 5.2.3.14, 6.1.3.4, 6.4.2.4, and 7.0.0.1 and later. CISA added CVE-2026-16812 to its Known Exploited Vulnerabilities catalog and ordered U.S. federal civilian executive branch agencies to mitigate the vulnerability by Thursday, July 30, 2026.

    Show sources