Arista VeloCloud Orchestrator Vulnerability Exploited, Prompting Urgent Security Measures
A critical security flaw in the Arista VeloCloud Orchestrator (VCO) has been actively exploited, leading to significant cybersecurity concerns. The vulnerability, identified as CVE-2026-16812, is a command injection flaw that allows for arbitrary code execution, potentially compromising the confidentiality, integrity, and availability of the orchestrator and its managed data. Arista has acknowledged the issue, which affects several versions of VCO, and has released patches to address the vulnerability. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this flaw to its Known Exploited Vulnerabilities catalog, mandating federal agencies to apply the patch by July 30, 2026. The exploitation of this vulnerability highlights the ongoing challenges in securing network infrastructure against sophisticated cyber threats.