Arista patches VeloCloud Orchestrator zero-day exploited in attacks
7 Articles
7 Articles
Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock
A critical flaw in Arista's VeloCloud Orchestrator has gone from zero to KEV in short order, with the networking giant confirming attackers are already exploiting it. The vulnerability, tracked as CVE-2026-16812, carries a maximum CVSS score of 10.0 and affects VeloCloud Orchestrator On-Prem, the self-hosted version of the software that enterprises use to centrally manage VeloCloud software-defined wide area networks (SD-WANs) connecting branch …
A critical vulnerability in Arista VeloCloud Orchestrator is actively exploited. CISA puts the gap with a maximum of 10.0 on the KEV list. A critical vulnerability in local installations of the Arista VeloCloud Orchestrator (VCO) is currently actively exploited. The vulnerability is managed under the CVE-2026-16812 identifier and reaches the maximum CVSS severity of 10.0. It is an operating system command injection that allows the execution of a…
Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day
Impacting on-premises deployments, the OS command injection allows attackers to access privileged internal functionality. The post Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day appeared first on SecurityWeek.
The IT security agency CISA reports attacks on vulnerabilities in Fortinet FortiOS and Arista VeloCloud.
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium




