logo

CVE-2026-16812: VeloCloud Orchestrator OS Command Injection (CVSS 10) Exploited in the Wild

ID: f30a14cf-97be-5f2f-9931-03efb095eeb9

STIX ID: report--f30a14cf-97be-5f2f-9931-03efb095eeb9

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-07-27

Date Updated: 2026-07-28

Author: Do Son

...
...

**Arista VeloCloud Orchestrator command injection (CVE-2026-16812) under active attack — apply patches immediately.** Arista confirmed a critical, unauthenticated OS command injection (CVSS 10.0) actively exploited in the wild against on‑prem VCO; two additional patched issues (SQLi and SSRF) were identified but not seen exploited. Upgrade to the fixed releases (5.2.3.14, 6.1.3.4, 6.4.2.4, 7.0.0.1), restrict access to the VCO web interface, block the listed attacker IPs, and review logs for signs of command execution or unexpected outbound connections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.