Home / Jul 29, 2026 / Story
0
#8 SecurityWeek general July 28, 2026 at 06:40 UTC

Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day

By Ionut Arghire

AI Summary

A critical OS command injection vulnerability in on-premises Arista VeloCloud Orchestrator has been confirmed as exploited as a zero-day in the wild, allowing attackers to access privileged internal functionality and execute arbitrary code. The flaw affects only on-premises deployments of VCO, Arista's SD-WAN management platform used in enterprise and service provider environments. Security teams managing VeloCloud infrastructure should audit for indicators of compromise in addition to applying available patches.

Relevance score: 83.0/100

# More from July 29