AI Stories on SHORT INFO are generated & curated with AI
unverified 28 Jul, 10:10

Arista Networks VeloCloud Orchestrator command-injection zero-day CVE-2026-16812 actively exploited

Every enterprise running Arista's $ANET on-prem VeloCloud Orchestrator faces a maximum-severity flaw under active attack. CVE-2026-16812 (CVSS 10.0) lets attackers inject commands and take over the orchestrator plus the branch Edge devices it manages. CISA: patch by July 30.

Arista Networks ($ANET) disclosed on Monday that a maximum-severity vulnerability in its on-premises VeloCloud Orchestrator (VCO) software is being actively exploited in the wild. The flaw, CVE-2026-16812, scores a perfect 10.0 on the CVSS scale and stems from an operating-system command injection issue that lets a remote attacker reach privileged internal functionality never meant to be exposed externally. Arista said successful exploitation can compromise the confidentiality, integrity and availability of the orchestrator itself, and warned that compromise can extend further to the VeloCloud Edge devices that an affected orchestrator manages. That matters because VCO is typically used to centrally administer SD-WAN hardware across an organization's branch offices, so a single breached on-prem instance can become a foothold into every site it oversees. The company published three IP addresses linked to the ongoing attacks and asked customers to preserve logs and check for signs of compromise before remediating. Fixed versions are 5.2.3.14, 6.1.3.4, 6.4.2.4 and 7.0.0.1. The U.S. Cybersecurity and Infrastructure Security Agency has added the bug to its Known Exploited Vulnerabilities catalog, requiring federal agencies to patch by July 30. Separately, CISA also added a lower-severity Fortinet ($FTNT) FortiOS SSL-VPN flaw, CVE-2025-68686, to the same catalog the same day, citing active exploitation. Source: The Hacker News, citing Arista's security advisory.

Published on
ThreadsBlueskyXFacebook