The bottom line: The maximum criticality of CVE-2026-16812 in Arista VeloCloud Orchestrator On-Premises with CVSS 10.0 is being actively exploited by attackers for remote code execution.
A critical command-injection vulnerability (CVE-2026-16812, CVSS 10.0) in the on-premises version of Arista VeloCloud Orchestrator is currently being actively exploited in the field, enabling unauthenticated attackers to execute arbitrary code remotely.
VeloCloud Orchestrator (VCO) in the on-premises variant contains a command-injection vulnerability that allows direct operating system command execution on the affected host. The vulnerability tracked as CVE-2026-16812 receives the maximum CVSS score of 10.0.
Arista customers with self-hosted VCO deployments should assume that attackers are already operationally exploiting this vulnerability. The vulnerability enables system commands to be executed without prior authentication, thereby gaining complete control over the VCO instance.
CISOs should immediately verify whether VeloCloud Orchestrator On-Premises is operating in their infrastructure, analyze access patterns, and follow Arista’s published security advisory for patches or mitigations. These systems are typically central to WAN orchestration in hybrid and multi-cloud environments and therefore require the highest priority in incident response.
Source: thehackernews.com · Published July 28, 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.7.3.