bleeping-computer · Crawled Jul 27, 2026

Arista patches VeloCloud Orchestrator zero-day exploited in attacks

3 IoCs
Read original article ↗

AI Summary

Arista has patched a critical command injection vulnerability, CVE-2026-16812, in on-premises VeloCloud Orchestrator (VCO) deployments that is being actively exploited. The flaw allows unauthenticated remote attackers to execute privileged OS commands, compromising the confidentiality, integrity, and availability of the orchestrator and managed data. Exploitation requires only network access to the VCO web interface, with no credentials needed, and the U.S. CISA has mandated federal agencies to mitigate the issue by July 30, 2026.

AI-extracted · verify before operational use

Indicators of Compromise 3 extracted

Type Value Detail
IP 8[.]19[.]75[.]217 Details →
IP 206[.]72[.]242[.]124 Details →
IP 206[.]72[.]242[.]162 Details →