← Back to Feed

Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability

CVE-2026-16812

July 31, 2026 · CISA · Severity: CRITICAL

Arista's VeloCloud Orchestrator On-Prem contains a critical OS command injection vulnerability (CVE-2026-16812) that allows remote attackers to execute privileged commands on the system. Successful exploitation could compromise the VCO host, enabling unauthorized access to internal functionality and potentially affecting the confidentiality, integrity, and availability of both the orchestrator and its managed data. CISA confirmed this vulnerability is actively being exploited in the wild as of July 27, 2026. Organizations using Arista’s VeloCloud Orchestrator On-Prem are at risk, as attackers could leverage this flaw to gain control over critical network management functions. The inclusion in CISA’s Known Exploited Vulnerabilities catalog underscores the urgency for affected entities to apply patches or mitigations immediately to prevent potential breaches. This vulnerability highlights the persistent threat of unpatched software in enterprise networking environments.

Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Vendor: Arista Product: VeloCloud Orchestrator CISA Date Added: 2026-07-27 CVE: CVE-2026-16812 This vulnerability is actively exploited in the wild according to CISA Known Exploited Vulnerabilities catalog.

Key Takeaways

  • CVE-2026-16812 is actively exploited in the wild and has been added to the CISA Known Exploited Vulnerabilities catalog.
  • The vulnerability allows SQL injection attacks, which can lead to data theft, authentication bypass, or remote code execution.
  • Arista VeloCloud Orchestrator: Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host.
☕ Buy a Coffee