Attackers Actively Exploiting Maximum-Severity Command Injection Flaw in Arista VeloCloud Orchestrator

AI-generated NewsSnap summary based on source reporting.
Published: 2026-07-28
Category: technology
Source: The Hacker News

A critical security vulnerability (CVE-2026-16812) in on-premises versions of Arista VeloCloud Orchestrator (VCO) is under active exploitation. The flaw, an operating system command injection with a CVSS score of 10.0, could allow remote attackers to execute arbitrary code and compromise the confidentiality, integrity, and availability of the orchestrator. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this flaw to its Known Exploited Vulnerabilities (KEV) catalog.

Context

CVE-2026-16812 is a command injection vulnerability that affects on-premises versions of Arista VeloCloud Orchestrator, with a maximum CVSS score of 10.0 indicating its critical nature. This flaw allows attackers to execute arbitrary commands remotely, threatening the security of affected systems. The U.S. Cybersecurity and Infrastructure Security Agency has recognized the severity of this issue by including it in the Known Exploited Vulnerabilities catalog.

Why it matters

The exploitation of this vulnerability poses significant risks to organizations using Arista VeloCloud Orchestrator, potentially leading to unauthorized access and control over critical systems. Given the high severity rating, immediate action is necessary to mitigate the threat. The situation highlights the ongoing challenges in cybersecurity and the need for vigilance against emerging vulnerabilities.

Implications

Successful exploitation of this vulnerability could lead to significant data breaches and operational disruptions for affected organizations. Businesses relying on VeloCloud Orchestrator may face reputational damage and financial losses. The incident underscores the importance of timely vulnerability management and the potential consequences of neglecting cybersecurity measures.

What to watch

Organizations using Arista VeloCloud Orchestrator should prioritize patching their systems to address this vulnerability. Monitoring for unusual activity and potential exploitation attempts will be crucial in the coming weeks. Additionally, updates from CISA and Arista regarding mitigation strategies and patches will be important to follow.

Want more?

Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.

Open NewsSnap.ai