Critical Arista VeloCloud Orchestrator Zero-Day Vulnerability Actively Exploited
A maximum-severity security flaw (CVE-2026-16812) in on-premises versions of Arista VeloCloud Orchestrator (VCO) is currently being actively exploited as a zero-day. This operating system command injection vulnerability allows remote attackers to access privileged internal functionality and execute arbitrary code on the VCO host. Arista has issued an advisory, urging users to address the critical security risk.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.