Hackers Actively Exploiting Critical Arista VeloCloud Vulnerability (CVE-2026-16812)

Arista Networks has issued a warning regarding active exploitation of CVE-2026-16812, a critical unauthenticated OS command injection flaw in on-premises VeloCloud Orchestrator (VCO) deployments. The vulnerability, with a CVSS score of 10.0, allows remote attackers to access privileged internal functions and potentially compromise the orchestrator host. Organizations are advised to block identified malicious IP addresses and review logs for anomalous web requests.

Want more?

Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.

Open NewsSnap.ai