Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
What happened
A critical OS command injection vulnerability (CVE-2026-16812) in on-premises Arista VeloCloud Orchestrator is under active exploitation. The flaw carries a CVSS score of 10.0 and allows attackers to execute arbitrary code.
Why it ranks #1
Highest priority due to confirmed active exploitation of a maximum-severity (CVSS 10.0) vulnerability in enterprise infrastructure.
Who should care
IT and platform operations, SOC and incident response teams
What to do
Apply the Arista patch for VeloCloud Orchestrator immediately.
- Impact
- high
- Urgency
- near-term
- Confidence
- high
- Scope
- enterprise
- Status
- disclosed