logo

Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw

ID: 8a2e3fba-f59d-5338-b09b-653d62aa4f24

STIX ID: report--8a2e3fba-f59d-5338-b09b-653d62aa4f24

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-07-28

Date Updated: 2026-07-28

Author: [email protected] (The Hacker News)

...
...

### Executive Summary A critical OS command injection vulnerability (CVE-2026-16812, CVSS 10.0) in on‑premises Arista VeloCloud Orchestrator is being actively exploited in the wild; Arista published affected versions, three malicious source IPs as IoCs, and mitigation steps, and CISA added the flaw to its Known Exploited Vulnerabilities catalog. The report also briefly notes active exploitation or risk for other vulnerabilities (a Fortinet FortiOS SSL‑VPN issue and an unpatched Alibaba Fastjson RCE) and advises log preservation, patching, access restrictions, and review of administrator and outbound activity where compromise is suspected.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.