← Back to Feed
Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
CVE-2026-16812
July 28, 2026 · The Hacker News · Severity: HIGH
A maximum-severity OS command injection flaw (CVE-2026-16812, CVSS 10.0) in on-premises Arista VeloCloud Orchestrator (VCO) is under active exploitation in the wild. Arista addressed the issue in hosted and dedicated versions in advance and released patches for on-prem versions 5.2.3.14, 6.1.3.4, 6.4.2.4, and 7.0.0.1. The functionality exploited was intended for internal use only.
Key Takeaways
- CVE-2026-16812 (CVSS 10.0) is a maximum-severity OS command injection in Arista VeloCloud Orchestrator
- Remote attackers can access privileged internal functionality and compromise the VCO host
- The vulnerability is under active exploitation in the wild