# Arista patches VeloCloud Orchestrator zero-day exploited in attacks

_Monday, July 27, 2026 at 8:00 AM EDT · Security · Latest · Tier 2 — Notable_

![Arista patches VeloCloud Orchestrator zero-day exploited in attacks — Primary](https://www.bleepstatic.com/content/hl-images/2026/07/27/arista-logo-globe.jpg)

Arista Networks has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks, the company said Monday. The flaw, tracked as CVE-2026-16812, carries a severity score of 10.0 and allows unauthenticated remote attackers to access privileged functionality intended only for internal use.

Arista said in a security advisory that the vulnerability affects VCO versions 5.2.x before 5.2.3.14, 6.1.x before 6.1.3.4, 6.4.x before 6.4.2.4, and 7.0.x before 7.0.0.1. The company said VCO is supposed to be exposed by default with no configuration option to prevent exposure, and attackers only need network access to the web interface to exploit the flaw. Hosted and dedicated deployments were patched before the advisory was published and are not affected.

The U.S. Cybersecurity and Infrastructure Security Agency added the vulnerability to its Known Exploited Vulnerabilities catalog and ordered federal civilian executive branch agencies to mitigate it by July 30. Arista shared three IP addresses observed exploiting the vulnerability and urged administrators to restrict access to administrative networks, monitor logs, and review for signs of compromise including unusual web requests and unauthorized configuration changes.

## Sources

- [Bleeping Computer](https://www.bleepingcomputer.com/news/security/arista-patches-velocloud-orchestrator-zero-day-exploited-in-attacks/)

---
Canonical: https://techandbusiness.org/newswire/qiVFXjFXunc8pg72eHE-iw
Retrieved: 2026-07-28T03:28:36.225Z
Publisher: Tech & Business (techandbusiness.org)
