hacker-news · Crawled Jul 28, 2026

Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw

3 IoCs
Read original article ↗

AI Summary

A critical command injection vulnerability, CVE-2026-16812, in on-premises versions of Arista VeloCloud Orchestrator (VCO) is under active exploitation, allowing remote attackers to execute arbitrary code and compromise the confidentiality, integrity, and availability of the system. The flaw affects multiple VCO versions prior to specific patched releases and has been added to CISA's Known Exploited Vulnerabilities catalog, requiring federal agencies to patch by July 30, 2026. Arista has provided three malicious IP addresses as indicators of compromise and recommends immediate remediation or network access restrictions to mitigate risk.

AI-extracted · verify before operational use

Indicators of Compromise 3 extracted

Type Value Detail
IP 8[.]19[.]75[.]217 Details →
IP 206[.]72[.]242[.]124 Details →
IP 206[.]72[.]242[.]162 Details →