Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw

Summary

A critical command injection vulnerability (CVE-2026-16812) affecting on-premises Arista VeloCloud Orchestrator (VCO) versions is being actively exploited in the wild. This flaw allows for arbitrary code execution and carries a CVSS score of 10.0.

IFF Assessment

FOE

This vulnerability allows for arbitrary code execution, which is a severe threat to defenders.

Severity

10.0 Critical

The vulnerability is a maximum-severity operating system command injection flaw, allowing for arbitrary code execution, which is the highest possible impact.

CISA KEV: Listed as actively exploited. Federal patch due: July 30, 2026. Known ransomware use: Unknown.

Defender Context

Defenders must prioritize patching or mitigating this critical vulnerability in Arista VeloCloud Orchestrator deployments to prevent unauthorized code execution. Attackers actively exploiting this flaw indicate a high likelihood of targeted attacks against organizations using this infrastructure.

Read Full Story →