SYS::ONLINE
Wasteland.
Briefs1585
Issues21
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-16812 2026-07-27

Arista VeloCloud Orchestrator On-Prem Hit With CVSS 10.0 Command Injection: CVE-2026-16812

"CISA added CVE-2026-16812 to the Known Exploited Vulnerabilities catalog on 2026-07-27, a maximum-severity OS command injection flaw in on-prem Arista VeloCloud Orchestrator that is already under active exploitation."

CISA added CVE-2026-16812 to the Known Exploited Vulnerabilities catalog on 2026-07-27, a maximum-severity OS command injection flaw in on-prem Arista VeloCloud Orchestrator that is already under active exploitation.

What Is It

CVE-2026-16812 is an OS command injection vulnerability (CWE-78) in VeloCloud Orchestrator (VCO) On-Prem. Internal-only functionality that was never intended to be remotely accessible can be reached by a remote attacker, allowing access to privileged internal functions and impact on the VCO host itself. Arista's PSIRT scores it CVSS 3.1 10.0 CRITICAL (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) and CVSS 4.0 10.0 CRITICAL. No authentication, no user interaction, low attack complexity, and scope change; the ceiling of the scoring system.

Why It Matters

KEV confirms active exploitation: the NVD record states the issue "was discovered externally and is known to be actively exploited." CISA's SSVC decision points list exploitation as active, automatable as yes, and technical impact as total. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and all data it manages. An orchestrator is a control-plane asset; compromise there reaches downstream managed infrastructure. Known ransomware campaign use is currently listed as Unknown.

What's Vulnerable

Arista Networks VeloCloud Orchestrator On-Prem, in these version ranges:

Per Arista, Hosted and Dedicated versions of VCO were patched in advance of the notice.

Patch Status

Fixed builds are 5.2.3.14, 6.1.3.4, 6.4.2.4, and 7.0.0.1. CISA's required action: apply mitigations per vendor instructions in compliance with BOD 26-04 (Prioritizing Security Updates Based on Risk) and CISA's Forensics Triage Requirements; follow applicable BOD 26-04 cloud-service guidance, or discontinue use of the product if mitigations are unavailable. Stakeholders must evaluate each asset's internet exposure. Due date: 2026-07-30: three days after KEV listing.

Sources