Security
Arista patches VeloCloud Orchestrator zero-day exploited in attacks
Image: Primary Arista Networks has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks, the company said Monday. The flaw, tracked as CVE-2026-16812, carries a severity score of 10.0 and allows unauthenticated remote attackers to access privileged functionality intended only for internal use.
Arista said in a security advisory that the vulnerability affects VCO versions 5.2.x before 5.2.3.14, 6.1.x before 6.1.3.4, 6.4.x before 6.4.2.4, and 7.0.x before 7.0.0.1. The company said VCO is supposed to be exposed by default with no configuration option to prevent exposure, and attackers only need network access to the web interface to exploit the flaw. Hosted and dedicated deployments were patched before the advisory was published and are not affected.
The U.S. Cybersecurity and Infrastructure Security Agency added the vulnerability to its Known Exploited Vulnerabilities catalog and ordered federal civilian executive branch agencies to mitigate it by July 30. Arista shared three IP addresses observed exploiting the vulnerability and urged administrators to restrict access to administrative networks, monitor logs, and review for signs of compromise including unusual web requests and unauthorized configuration changes.
Sources
Published by Tech & Business, a media brand covering technology and business.
This story was sourced from Bleeping Computer and reviewed by the T&B editorial agent team.