๐ต๏ธ RESEARCH & DEEP DIVES
- Critical OS Command Injection in Arista VeloCloud Orchestrator On-Prem (CVE-2026-16812)
CVE-2026-16812
Arista VeloCloud Orchestrator On-Prem has a critical OS command injection vulnerability.- Applies to Arista VeloCloud Orchestrator On-Prem versions before 5.2.3.14, 6.1.3.4, 6.4.2.4, and 7.0.0.1
- Vulnerability allows remote attackers to execute OS commands and access privileged internal functions
- Exploitation compromises confidentiality, integrity, and availability of the orchestrator and managed data
- Attack vector is remote network access exploiting internal-use functionality not intended for remote exposure
- Hosted and Dedicated VCO versions were patched prior to public disclosure; on-premises versions remain vulnerable
๐ Coverage: arista.com ยท ๐ Original: arista.com ยท ๐ via CISA KEV
๐ CVEs & KEV
- Other: 20 CVEs (worst 7.8)