Find notable cyber news and cases, enriched with sources, timelines, and signals.

VeloCloud Orchestrator unauthenticated OS command injection, actively exploited (CVE-2026-16812)

Vulnerability
First reported
Last updated
Happening score
H score 48
2 unique sources, 2 articles

Summary

Hide ▲

CVE-2026-16812 is a maximum-severity unauthenticated OS command injection in Arista VeloCloud Orchestrator (VCO) on-premises that is being actively exploited. The flaw can expose privileged internal functionality and lead to arbitrary code execution, with potential impact to the orchestrator’s confidentiality, integrity, and availability and to data managed by the orchestrator. Arista lists affected VCO 5.2.x, 6.1.x, 6.4.x, and 7.0.x release lines, and fixed releases are 5.2.3.14, 6.1.3.4, 6.4.2.4, and 7.0.0.1 or later. CISA added the CVE to its Known Exploited Vulnerabilities catalog and set a July 30, 2026 mitigation deadline for FCEB agencies.

Related Happenings

N-able N-central servers hit by network compromise

Incident
H score41 First: 03.08.2026 09:41 Last: 03.08.2026 09:41 Sources 1

About this happening: N-able N-central is part of an ongoing authentication-bypass compromise that let attackers gain remote administrative access and reach managed systems through Take C...

Latest development: 04.08.2026 10:00

CISA added CVE-2026-18577 in N-able N-central to the KEV catalog after reports of active exploitation, and N-able said a limited number of customers were compromised through the flaw. Successful exploitation can give attackers administrative access to vulnerable N-central servers and let them pivot through Take Control into managed endpoints.

CISA orders federal mitigation of CVE-2026-16812

Public Sector Action
H score36 First: 28.07.2026 01:49 Last: 28.07.2026 01:49 Sources 1

How related: The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add the flaw to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patch by July 30, 2026.

About this happening: CISA added CVE-2026-16812 to its Known Exploited Vulnerabilities catalog and ordered U.S. federal civilian executive branch agencies to mitigate it by July 30, 2...

Timeline

  1. 28.07.2026 01:49 3 articles · 10d ago

    Arista patches actively exploited CVE-2026-16812 in VeloCloud Orchestrator

    Initial Disclosure

    Arista disclosed that CVE-2026-16812 is a maximum-severity unauthenticated OS command injection in on-premises VeloCloud Orchestrator that is being actively exploited, allowing remote attackers to reach privileged internal functionality and potentially compromise the confidentiality, integrity, and availability of the orchestrator and the data it manages. Affected releases include VCO 5.2.x before 5.2.3.14, 6.1.x before 6.1.3.4, 6.4.x before 6.4.2.4, and 7.0.x before 7.0.0.1, while fixed versions include 5.2.3.14, 6.1.3.4, 6.4.2.4, and 7.0.0.1 and later. CISA added CVE-2026-16812 to its Known Exploited Vulnerabilities catalog and ordered U.S. federal civilian executive branch agencies to mitigate the vulnerability by Thursday, July 30, 2026.

    Show sources