Attackers Exploit CVSS 10 Security Flaw in Arista VeloCloud Orchestrator as CISA Orders Federal Agencies to Patch by July 30
Attackers are actively exploiting a CVSS 10.0 operating system command injection flaw in the on-premises version of Arista VeloCloud Orchestrator. The vulnerability, tracked as CVE-2026-16812, allows remote attackers to reach privileged internal functions and compromise the orchestrator and the data it manages.
From the sources (2 posts)
@thehackersnews🚨 Attackers are exploiting a CVSS 10.0 command injection flaw in on-prem Arista VeloCloud Orchestrator. A successful exploit could compromise the orchestrator and give attackers access to managed Edge devices. CISA has ordered federal agen
@rootcausehqActively exploited: CVE-2026-16812, OS command injection in Arista VeloCloud Orchestrator on-prem. A remote attacker reaches privileged internal functionality and compromises the orchestrator and the data it manages. CISA added it to KEV.