Critical Arista VeloCloud Flaw Lets Attackers Execute OS Commands Remotely
ID: 760eac2e-ec43-55b4-8837-d424d9159f7c
STIX ID: report--760eac2e-ec43-55b4-8837-d424d9159f7c
Feed Name: Cyber Press
Threat Score
**Executive Summary:** Arista disclosed a maximum-severity unauthenticated remote command-execution vulnerability (CVE-2026-16812) in on‑prem VeloCloud Orchestrator (CVSS 10.0) that is being actively exploited in the wild; Arista lists affected VCO versions, provides patched releases, recommends immediate patching and access restrictions, and published three IP addresses observed attacking.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
