top of page
perceptive_background_267k.jpg

Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionalit…

Published:

27 July 2026 at 00:00:00

Alert date:

27 July 2026 at 20:03:54

Source:

cisa.gov

Click to open the original link from this advisory

Network Infrastructure, Enterprise Applications, Zero-Day Vulnerabilities

CVE-2026-16812 is an OS command injection vulnerability in Arista VeloCloud Orchestrator On-Prem. A remote attacker can exploit this flaw to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and the data it manages. The vulnerability has been flagged by CISA under BOD 26-04, which prioritizes security updates based on risk. An official security advisory has been published by Arista. Organizations using the affected product are urged to apply patches promptly. The vulnerability is tracked in NVD as well.

Technical details

Mitigation steps:

Affected products:

Arista VeloCloud Orchestrator On-Prem

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page