Arista VeloCloud Orchestrator security update for CVE-2026-16812
Security Patch Release
Summary
Hide ▲
Show ▼
Arista patched CVE-2026-16812, a maximum-severity 10.0 OS command injection flaw in on-premises VeloCloud Orchestrator (VCO), after confirming it is actively exploited. Successful exploitation can expose privileged internal functionality and compromise the confidentiality, integrity, and availability of the orchestrator and managed data. The fix covers 5.2.x, 6.1.x, 6.4.x, and 7.0.x branches, while hosted and dedicated VCO versions were addressed in advance. CISA added the CVE to the Known Exploited Vulnerabilities catalog and set a July 30, 2026 deadline for FCEB agencies; Arista also shared three IP addresses as attacker IoCs.
Related Happenings
N-able security patch release for CVE-2026-18576
Security Patch Release
H score48
First: 05.08.2026 18:51
Last: 05.08.2026 18:51
Sources 1
About this happening:
N-able released an emergency hotfix for CVE-2026-18576 in N-central, closing an authentication flaw that let attackers hijack administrative accounts. The company urge...
N-able security patch release for CVE-2026-18576
Security Patch ReleaseAbout this happening: N-able released an emergency hotfix for CVE-2026-18576 in N-central, closing an authentication flaw that let attackers hijack administrative accounts. The company urge...
Paperclip security patch release for CVE-2026-41679
Security Patch Release
H score45
First: 05.08.2026 17:30
Last: 05.08.2026 17:30
Sources 1
About this happening:
Paperclip shipped 2026.416.0 and 0.3.1 to close three disclosed vulnerabilities that could expose data and enable unauthenticated command execution. The releas...
Paperclip security patch release for CVE-2026-41679
Security Patch ReleaseAbout this happening: Paperclip shipped 2026.416.0 and 0.3.1 to close three disclosed vulnerabilities that could expose data and enable unauthenticated command execution. The releas...
Veeam security patch release for CVE-2026-58073
Security Patch Release
H score39
First: 05.08.2026 17:27
Last: 05.08.2026 17:27
Sources 1
About this happening:
Veeam released Service Provider Console 9.3.0.35057 to fix four vulnerabilities in the multi-tenant backup management console. The most serious are CVE-2026-58073,...
Veeam security patch release for CVE-2026-58073
Security Patch ReleaseAbout this happening: Veeam released Service Provider Console 9.3.0.35057 to fix four vulnerabilities in the multi-tenant backup management console. The most serious are CVE-2026-58073,...
N-able security patch release for CVE-2026-18577
Security Patch Release
H score41
First: 03.08.2026 09:41
Last: 03.08.2026 09:41
Sources 1
About this happening:
N-able is warning that CVE-2026-18577 is being actively exploited against N-central on both hosted and on-premises servers. The vendor released hotfix 2026.3...
N-able security patch release for CVE-2026-18577
Security Patch ReleaseAbout this happening: N-able is warning that CVE-2026-18577 is being actively exploited against N-central on both hosted and on-premises servers. The vendor released hotfix 2026.3...
N-able N-central servers hit by network compromise
Incident
H score41
First: 03.08.2026 09:41
Last: 03.08.2026 09:41
Sources 1
About this happening:
N-able N-central is part of an ongoing authentication-bypass compromise that let attackers gain remote administrative access and reach managed systems through Take C...
N-able N-central servers hit by network compromise
IncidentAbout this happening: N-able N-central is part of an ongoing authentication-bypass compromise that let attackers gain remote administrative access and reach managed systems through Take C...
Latest development: 04.08.2026 10:00
CISA added CVE-2026-18577 in N-able N-central to the KEV catalog after reports of active exploitation, and N-able said a limited number of customers were compromised through the flaw. Successful exploitation can give attackers administrative access to vulnerable N-central servers and let them pivot through Take Control into managed endpoints.
Timeline
-
28.07.2026 01:49 3 articles · 10d ago
Arista patches actively exploited VeloCloud Orchestrator command injection flaw
Initial DisclosureArista patched CVE-2026-16812, an unauthenticated OS command injection flaw in on-premises VeloCloud Orchestrator, after confirming it is being actively exploited; successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and the data it manages. CISA also added the CVE to its Known Exploited Vulnerabilities catalog and directed U.S. federal civilian executive branch agencies to mitigate it by Thursday, July 30, 2026.
Show sources
- Arista patches VeloCloud Orchestrator zero-day exploited in attacks — www.bleepingcomputer.com — 28.07.2026 01:49
- Arista patches VeloCloud Orchestrator zero-day exploited in attacks — www.bleepingcomputer.com — 28.07.2026 01:49
- Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw — thehackernews.com — 28.07.2026 07:43