CRITICAL ⚡ MUST-KNOW
Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
A maximum-severity flaw in on-premises Arista VeloCloud Orchestrator (VCO), tracked as CVE-2026-16812 (CVSS 10.0), is under active exploitation. The vulnerability is an OS command injection that lets attackers reach privileged internal functionality and achieve arbitrary code execution. Arista has released a patch — on-prem VCO operators should update immediately.