#8
SecurityWeek
general
July 28, 2026 at 06:40 UTC
Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day
By Ionut Arghire
AI Summary
A critical OS command injection vulnerability in on-premises Arista VeloCloud Orchestrator has been confirmed as exploited as a zero-day in the wild, allowing attackers to access privileged internal functionality and execute arbitrary code. The flaw affects only on-premises deployments of VCO, Arista's SD-WAN management platform used in enterprise and service provider environments. Security teams managing VeloCloud infrastructure should audit for indicators of compromise in addition to applying available patches.
Relevance score: 83.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →