logo

Arista patches VeloCloud Orchestrator zero-day exploited in attacks

ID: 3b81c28e-9eeb-5398-bcee-672f88a328fc

STIX ID: report--3b81c28e-9eeb-5398-bcee-672f88a328fc

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2026-07-27

Date Updated: 2026-07-28

Author: Lawrence Abrams

...
...

Arista disclosed a critical unauthenticated OS command injection (CVE-2026-16812, CVSS 10.0) in on-premises VeloCloud Orchestrator that is actively exploited; affected VCO 5.2.x/6.1.x/6.4.x/7.0.x releases are listed with patched versions provided, CISA added the CVE to its Known Exploited Vulnerabilities catalog, and Arista published mitigation guidance and three IP addresses observed exploiting the flaw.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.