Post
CRITICAL ⚡ MUST-KNOW

Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw

· cve · zero-day · vulnerability

A maximum-severity flaw in on-premises Arista VeloCloud Orchestrator (VCO), tracked as CVE-2026-16812 (CVSS 10.0), is under active exploitation. The vulnerability is an OS command injection that lets attackers reach privileged internal functionality and achieve arbitrary code execution. Arista has released a patch — on-prem VCO operators should update immediately.