Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability
July 31, 2026 · CISA · Severity: CRITICAL
Arista's VeloCloud Orchestrator On-Prem contains a critical OS command injection vulnerability (CVE-2026-16812) that allows remote attackers to execute privileged commands on the system. Successful exploitation could compromise the VCO host, enabling unauthorized access to internal functionality and potentially affecting the confidentiality, integrity, and availability of both the orchestrator and its managed data. CISA confirmed this vulnerability is actively being exploited in the wild as of July 27, 2026. Organizations using Arista’s VeloCloud Orchestrator On-Prem are at risk, as attackers could leverage this flaw to gain control over critical network management functions. The inclusion in CISA’s Known Exploited Vulnerabilities catalog underscores the urgency for affected entities to apply patches or mitigations immediately to prevent potential breaches. This vulnerability highlights the persistent threat of unpatched software in enterprise networking environments.
Key Takeaways
- CVE-2026-16812 is actively exploited in the wild and has been added to the CISA Known Exploited Vulnerabilities catalog.
- The vulnerability allows SQL injection attacks, which can lead to data theft, authentication bypass, or remote code execution.
- Arista VeloCloud Orchestrator: Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host.