Find notable cyber news and cases, enriched with sources, timelines, and signals.

CISA orders federal mitigation of CVE-2026-16812

Public Sector Action
First reported
Last updated
Happening score
H score 36
2 unique sources, 2 articles

Summary

Hide ▲

CISA added CVE-2026-16812 to its Known Exploited Vulnerabilities catalog and ordered U.S. federal civilian executive branch agencies to mitigate it by July 30, 2026 under Binding Operational Directive 22-01. The action follows Arista’s disclosure that Arista VeloCloud Orchestrator (VCO) on-premises versions were hit by an actively exploited CVSS 10.0 command-injection flaw. Arista said successful exploitation could expose privileged internal functionality and compromise the orchestrator, its managed data, and, in some cases, VeloCloud Edge devices. The advisory also listed three IP addresses as attack indicators and urged customers to block them, review logs, and rotate credentials where compromise is suspected.

Related Happenings

N-able N-central servers hit by network compromise

Incident
H score41 First: 03.08.2026 09:41 Last: 03.08.2026 09:41 Sources 1

About this happening: N-able N-central is part of an ongoing authentication-bypass compromise that let attackers gain remote administrative access and reach managed systems through Take C...

Latest development: 04.08.2026 10:00

CISA added CVE-2026-18577 in N-able N-central to the KEV catalog after reports of active exploitation, and N-able said a limited number of customers were compromised through the flaw. Successful exploitation can give attackers administrative access to vulnerable N-central servers and let them pivot through Take Control into managed endpoints.

VeloCloud Orchestrator unauthenticated OS command injection, actively exploited (CVE-2026-16812)

Vulnerability
H score48 First: 28.07.2026 01:49 Last: 28.07.2026 01:49 Sources 1

How related: A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild.

About this happening: CVE-2026-16812 is a maximum-severity unauthenticated OS command injection in Arista VeloCloud Orchestrator (VCO) on-premises that is being actively exploited. The...

Arista VeloCloud Orchestrator security update for CVE-2026-16812

Security Patch Release
H score55 First: 28.07.2026 01:49 Last: 28.07.2026 01:49 Sources 1

How related: The company says the flaw is fixed in VCO versions 5.2.3.14, 6.1.3.4, and 6.4.2.4 and later.

About this happening: Arista patched CVE-2026-16812, a maximum-severity 10.0 OS command injection flaw in on-premises VeloCloud Orchestrator (VCO), after confirming it is actively...

CISA BOD 26-04 prioritizes vulnerability remediation for federal civilian agencies

Public Sector Action
H score27 First: 10.06.2026 15:00 Last: 10.06.2026 15:00 Sources 1

About this happening: CISA issued Binding Operational Directive 26-04 to require federal civilian agencies to prioritize vulnerability remediation using Asset Exposure, KEV Status,...

Cisco security patch release for CVE-2026-20188

Security Patch Release
H score35 First: 06.05.2026 21:06 Last: 06.05.2026 21:06 Sources 1

About this happening: Cisco released security updates for CVE-2026-20188, a high-severity DoS vulnerability in Crosswork Network Controller (CNC) and Network Services Orchestrator (NS...

Timeline

  1. 28.07.2026 01:49 1 articles · 10d ago

    Arista patches actively exploited VeloCloud Orchestrator command injection

    Initial Disclosure

    Arista patched CVE-2026-16812 in on-premises VeloCloud Orchestrator, an unauthenticated OS command injection rated 10.0, and said the flaw was already being actively exploited to reach privileged internal functionality and could compromise the orchestrator and the data it manages. The affected releases were VCO 5.2.x before 5.2.3.14, 6.1.x before 6.1.3.4, 6.4.x before 6.4.2.4, and 7.0.x before 7.0.0.1.

    Show sources
  2. 28.07.2026 01:49 3 articles · 10d ago

    CISA orders federal mitigation of CVE-2026-16812

    Legal Policy Action Update

    CISA added CVE-2026-16812 to the Known Exploited Vulnerabilities catalog and ordered U.S. federal civilian executive branch agencies to mitigate the flaw by Thursday, July 30, 2026, under Binding Operational Directive 22-01. The federal directive treats the vulnerability as actively exploited and requires remediation on the public-sector timetable.

    Show sources