#2
The Hacker News
general
July 28, 2026 at 04:43 UTC
Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
By [email protected] (The Hacker News)
AI Summary
CVE-2026-16812, a CVSS 10.0 OS command injection flaw in on-premises Arista VeloCloud Orchestrator (VCO), is being actively exploited in the wild, allowing unauthenticated arbitrary code execution on SD-WAN management infrastructure. Arista has confirmed the vulnerability affects on-prem deployments only, with attackers able to access privileged internal functionality. Network operations and SD-WAN administrators should prioritize patching immediately given active exploitation.
Relevance score: 91.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →