HIGHVulnerability
Verified
Global

CISA KEV: Arista VeloCloud Orchestrator — Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability

·Source: CISA KEV

Updated:

Executive Summary

Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.

Analysis

Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Added to CISA Known Exploited Vulnerabilities catalog on 2026-07-27. Remediation due: 2026-07-30.

Indicators of Compromise (1)

CVE (1)
CVE-2026-16812
Source Attribution

Originally published by CISA KEV on Jul 27, 2026. Verified by: CISA.

Related Threats