CISA added CVE-2026-16812 to the Known Exploited Vulnerabilities catalog on 2026-07-27, a maximum-severity OS command injection flaw in on-prem Arista VeloCloud Orchestrator that is already under active exploitation.
What Is It
CVE-2026-16812 is an OS command injection vulnerability (CWE-78) in VeloCloud Orchestrator (VCO) On-Prem. Internal-only functionality that was never intended to be remotely accessible can be reached by a remote attacker, allowing access to privileged internal functions and impact on the VCO host itself. Arista's PSIRT scores it CVSS 3.1 10.0 CRITICAL (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) and CVSS 4.0 10.0 CRITICAL. No authentication, no user interaction, low attack complexity, and scope change; the ceiling of the scoring system.
Why It Matters
KEV confirms active exploitation: the NVD record states the issue "was discovered externally and is known to be actively exploited." CISA's SSVC decision points list exploitation as active, automatable as yes, and technical impact as total. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and all data it manages. An orchestrator is a control-plane asset; compromise there reaches downstream managed infrastructure. Known ransomware campaign use is currently listed as Unknown.
What's Vulnerable
Arista Networks VeloCloud Orchestrator On-Prem, in these version ranges:
- 5.2.0 through versions before 5.2.3.14
- 6.1.0 through versions before 6.1.3.4
- 6.4.0 through versions before 6.4.2.4
- 7.0.0 through versions before 7.0.0.1
Per Arista, Hosted and Dedicated versions of VCO were patched in advance of the notice.
Patch Status
Fixed builds are 5.2.3.14, 6.1.3.4, 6.4.2.4, and 7.0.0.1. CISA's required action: apply mitigations per vendor instructions in compliance with BOD 26-04 (Prioritizing Security Updates Based on Risk) and CISA's Forensics Triage Requirements; follow applicable BOD 26-04 cloud-service guidance, or discontinue use of the product if mitigations are unavailable. Stakeholders must evaluate each asset's internet exposure. Due date: 2026-07-30: three days after KEV listing.
Sources
- Arista Security Advisory 0144; https://www.arista.com/en/support/advisories-notices/security-advisory/24364-security-advisory-0144
- CISA Known Exploited Vulnerabilities Catalog; https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-16812
- NVD, CVE-2026-16812, https://nvd.nist.gov/vuln/detail/CVE-2026-16812
- CISA BOD 26-04; https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
- CISA BOD 26-04 Implementation Guidance / Forensics Triage Requirements; https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk