Home / Jul 29, 2026 / Story
0
#2 The Hacker News general July 28, 2026 at 04:43 UTC

Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw

By [email protected] (The Hacker News)

AI Summary

CVE-2026-16812, a CVSS 10.0 OS command injection flaw in on-premises Arista VeloCloud Orchestrator (VCO), is being actively exploited in the wild, allowing unauthenticated arbitrary code execution on SD-WAN management infrastructure. Arista has confirmed the vulnerability affects on-prem deployments only, with attackers able to access privileged internal functionality. Network operations and SD-WAN administrators should prioritize patching immediately given active exploitation.

Relevance score: 91.0/100

# More from July 29