CVE Tools

Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day

SecurityWeekBy Ionut Arghire

Reported exploitedVeloCloud Orchestrator

Our summary

Arista Networks disclosed a critical OS injection vulnerability in its VeloCloud Orchestrator platform, tracked as CVE-2026-16812, which has already been exploited in attacks. The flaw allows unauthenticated attackers to access privileged functions remotely, potentially compromising data confidentiality, integrity, and availability. Patches are available in versions 5.2.3.14, 6.1.3.4, 6.4.2.4, and 7.0.0.1. CISA added the vulnerability to its KEV catalog, urging immediate remediation.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store