← Back to Feed

Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw

CVE-2026-16812

July 28, 2026 · The Hacker News · Severity: HIGH

A maximum-severity OS command injection flaw (CVE-2026-16812, CVSS 10.0) in on-premises Arista VeloCloud Orchestrator (VCO) is under active exploitation in the wild. Arista addressed the issue in hosted and dedicated versions in advance and released patches for on-prem versions 5.2.3.14, 6.1.3.4, 6.4.2.4, and 7.0.0.1. The functionality exploited was intended for internal use only.

Key Takeaways

  • CVE-2026-16812 (CVSS 10.0) is a maximum-severity OS command injection in Arista VeloCloud Orchestrator
  • Remote attackers can access privileged internal functionality and compromise the VCO host
  • The vulnerability is under active exploitation in the wild
☕ Buy a Coffee