Overview
- Arista disclosed on Monday that it patched a maximum‑severity unauthenticated OS command‑injection flaw (CVE-2026-16812) in on‑premises VeloCloud Orchestrator and confirmed the bug is being actively exploited.
- The flaw allows any attacker with network access to a VCO web UI to run operating‑system commands and reach internal‑only management functions, creating risk to orchestrator data, credentials, certificates, and managed Edge devices.
- On‑prem VCO releases before 5.2.3.14, 6.1.3.4, 6.4.2.4 and 7.0.0.1 are affected while Hosted/Dedicated VCOs were already patched and VeloCloud Edge/Gateway products are not vulnerable.
- Arista published three IP addresses seen exploiting the bug and advised operators to block those IPs, restrict web UI access to management networks, preserve logs and timestamps, rotate credentials and certificates, and hunt for indicators of compromise.
- The U.S. CISA added the CVE to its Known Exploited Vulnerabilities catalog and ordered federal agencies to mitigate by July 30, and responders warn that installing patches may not remove existing breaches so forensic checks and possible rebuilds are likely needed.