3w ago · bleeping-computer
Arista has patched a critical command injection vulnerability, CVE-2026-16812, in on-premises VeloCloud Orchestrator (VCO) deployments that is being actively exploited. The flaw allows unauthenticated remote attackers to execute privileged OS commands, compromising the confidentiality, integrity, and availability of the orchestrator and managed data. Exploitation requires only network access to the VCO web interface, with no credentials needed, and the U.S. CISA has mandated federal agencies to mitigate the issue by July 30, 2026.