AI Stories on SHORT INFO are generated & curated with AI
unverified 29 Jul, 08:11

Arista VeloCloud Orchestrator CVE-2026-16812 maximum-severity flaw

A maximum-severity flaw (CVSS 10.0) in Arista $ANET VeloCloud Orchestrator is being actively exploited, letting attackers run commands with no login required. CISA has ordered US federal agencies to patch by July 30. Source: The Hacker News, BleepingComputer.

A newly disclosed command injection flaw in Arista $ANET VeloCloud Orchestrator (CVE-2026-16812) has scored a perfect 10.0 on the CVSS severity scale, the maximum possible rating. Arista confirmed the bug is being actively exploited in the wild by unauthenticated attackers who need no credentials to run commands on the orchestrator host. The company says its cloud-hosted and dedicated VCO deployments were already patched before the public advisory, but on-premise versions remain exposed until updated. The US Cybersecurity and Infrastructure Security Agency has added the flaw to its Known Exploited Vulnerabilities catalog and ordered federal civilian agencies to mitigate it by July 30, 2026. Source: The Hacker News, BleepingComputer.

#cyber
Published on
YouTubeBlueskyX