Post
CRITICAL ⚡ MUST-KNOW

Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw

· rce · vulnerability · zero-day · cve

A maximum-severity vulnerability in on-premises Arista VeloCloud Orchestrator (VCO), tracked as CVE-2026-16812 (CVSS 10.0), is under active exploitation in the wild. The flaw is an operating system command injection issue that lets attackers execute arbitrary code without authentication. Organizations running on-prem VCO should patch immediately and check logs for signs of compromise given confirmed in-the-wild exploitation.