Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
Reported exploitedVeloCloud OrchestratorOur summary
A high-severity command injection vulnerability in Arista VeloCloud Orchestrator (CVE-2026-16812) is currently being actively exploited in real-world attacks. The flaw allows remote attackers to execute arbitrary code, potentially compromising the orchestrator’s systems and data. Affected versions include all on-premises deployments of VCO 5.2.x before 5.2.3.14, 6.1.x before 6.1.3.4, 6.4.x before 6.4.2.4, and 7.0.x before 7.0.0.1. Arista has issued a security advisory and recommends immediate patching or restricting access until updates can be applied.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.