HIGHVulnerability
Global

Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw

·Source: The Hacker News

Updated:

Executive Summary

A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-16812 (CVSS score: 10.0), is a case of operating system command injection that could pave the way for arbitrary code execution. "VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue

Analysis

A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-16812 (CVSS score: 10.0), is a case of operating system command injection that could pave the way for arbitrary code execution. "VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue

Indicators of Compromise (1)

CVE (1)
CVE-2026-16812
Source Attribution

Originally published by The Hacker News on Jul 28, 2026.

Related Threats