Home / Jul 28, 2026 / Story
0
#3 BleepingComputer general July 27, 2026 at 22:49 UTC

Arista patches VeloCloud Orchestrator zero-day exploited in attacks

By Lawrence Abrams

AI Summary

Arista patched a maximum-severity (CVSS 10.0) command injection zero-day in on-premises VeloCloud Orchestrator deployments that is actively being exploited in the wild. Network administrators running on-prem VeloCloud Orchestrator instances should apply the patch immediately given active exploitation and the critical severity rating.

Relevance score: 86.0/100

# More from July 28