CVE Tools

Arista patches VeloCloud Orchestrator zero-day exploited in attacks

BleepingComputerBy Lawrence Abrams

Reported exploitedVeloCloud Orchestrator

Our summary

Arista has released a critical patch for a zero-day vulnerability in VeloCloud Orchestrator that is currently being exploited in real-world attacks. The flaw, identified as CVE-2026-16812, allows remote attackers to execute arbitrary commands without authentication, potentially leading to full system compromise. This high-severity issue affects several on-premises versions of the software, including those prior to 5.2.3.14, 6.1.3.4, and 6.4.2.4. Arista confirmed the vulnerability was discovered externally and is actively under attack, though details about the threat actors remain undisclosed. CISA has added the flaw to its Known Exploited Vulnerabilities list and mandated mitigation by July 30, 2026.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store