Arista Networks Patches Critical VeloCloud Orchestrator Vulnerability Exploited as Zero-Day
Arista Networks has released patches for a critical OS injection vulnerability in its VeloCloud Orchestrator (VCO) platform, identified as CVE-2026-16812. This vulnerability, which has a maximum CVSS score of 10, allows remote exploitation to access privileged functionalities intended for internal use. The flaw affects only the VeloCloud Orchestrator On-Prem and has been actively exploited in the wild as a zero-day. Arista has addressed the issue in VCO versions 5.2.3.14, 6.1.3.4, 6.4.2.4, and 7.0.0.1. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its Known Exploited Vulnerabilities catalog, urging federal agencies to patch it within three days.