A Vulnerability in VeloCloud Orchestrator (VCO) On-Prem Could Allow for Remote Code Execution
ID: 1d4861ac-d02c-5547-89a6-dc3915a68ee7
STIX ID: report--1d4861ac-d02c-5547-89a6-dc3915a68ee7
Feed Name: CISecurity.org Advisories
Threat Score
**CVE-2026-16812:** A remote code execution vulnerability in VeloCloud Orchestrator (VCO) On‑Prem allows unauthenticated attackers with network access to the VCO web interface to access privileged internal functionality and potentially execute commands, install programs, view/change/delete data, or create accounts; vulnerable VCO versions are exposed by default and cannot be configured to prevent the exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
