logo

A Vulnerability in VeloCloud Orchestrator (VCO) On-Prem Could Allow for Remote Code Execution

ID: 1d4861ac-d02c-5547-89a6-dc3915a68ee7

STIX ID: report--1d4861ac-d02c-5547-89a6-dc3915a68ee7

Feed Name: CISecurity.org Advisories

Threat Score
75/100

Date Published: 2026-07-28

Date Updated: 2026-07-29

...
...

**CVE-2026-16812:** A remote code execution vulnerability in VeloCloud Orchestrator (VCO) On‑Prem allows unauthenticated attackers with network access to the VCO web interface to access privileged internal functionality and potentially execute commands, install programs, view/change/delete data, or create accounts; vulnerable VCO versions are exposed by default and cannot be configured to prevent the exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.