VeloCloud Orchestrator unauthenticated OS command injection, actively exploited (CVE-2026-16812)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2026-16812 is a maximum-severity unauthenticated OS command injection in Arista VeloCloud Orchestrator (VCO) on-premises that is being actively exploited. The flaw can expose privileged internal functionality and lead to arbitrary code execution, with potential impact to the orchestrator’s confidentiality, integrity, and availability and to data managed by the orchestrator. Arista lists affected VCO 5.2.x, 6.1.x, 6.4.x, and 7.0.x release lines, and fixed releases are 5.2.3.14, 6.1.3.4, 6.4.2.4, and 7.0.0.1 or later. CISA added the CVE to its Known Exploited Vulnerabilities catalog and set a July 30, 2026 mitigation deadline for FCEB agencies.
Related Happenings
N-able N-central servers hit by network compromise
Incident
H score41
First: 03.08.2026 09:41
Last: 03.08.2026 09:41
Sources 1
About this happening:
N-able N-central is part of an ongoing authentication-bypass compromise that let attackers gain remote administrative access and reach managed systems through Take C...
N-able N-central servers hit by network compromise
IncidentAbout this happening: N-able N-central is part of an ongoing authentication-bypass compromise that let attackers gain remote administrative access and reach managed systems through Take C...
Latest development: 04.08.2026 10:00
CISA added CVE-2026-18577 in N-able N-central to the KEV catalog after reports of active exploitation, and N-able said a limited number of customers were compromised through the flaw. Successful exploitation can give attackers administrative access to vulnerable N-central servers and let them pivot through Take Control into managed endpoints.
CISA orders federal mitigation of CVE-2026-16812
Public Sector Action
H score36
First: 28.07.2026 01:49
Last: 28.07.2026 01:49
Sources 1
How related:
The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add the flaw to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patch by July 30, 2026.
About this happening:
CISA added CVE-2026-16812 to its Known Exploited Vulnerabilities catalog and ordered U.S. federal civilian executive branch agencies to mitigate it by July 30, 2...
CISA orders federal mitigation of CVE-2026-16812
Public Sector ActionHow related: The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add the flaw to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patch by July 30, 2026.
About this happening: CISA added CVE-2026-16812 to its Known Exploited Vulnerabilities catalog and ordered U.S. federal civilian executive branch agencies to mitigate it by July 30, 2...
Timeline
-
28.07.2026 01:49 3 articles · 10d ago
Arista patches actively exploited CVE-2026-16812 in VeloCloud Orchestrator
Initial DisclosureArista disclosed that CVE-2026-16812 is a maximum-severity unauthenticated OS command injection in on-premises VeloCloud Orchestrator that is being actively exploited, allowing remote attackers to reach privileged internal functionality and potentially compromise the confidentiality, integrity, and availability of the orchestrator and the data it manages. Affected releases include VCO 5.2.x before 5.2.3.14, 6.1.x before 6.1.3.4, 6.4.x before 6.4.2.4, and 7.0.x before 7.0.0.1, while fixed versions include 5.2.3.14, 6.1.3.4, 6.4.2.4, and 7.0.0.1 and later. CISA added CVE-2026-16812 to its Known Exploited Vulnerabilities catalog and ordered U.S. federal civilian executive branch agencies to mitigate the vulnerability by Thursday, July 30, 2026.
Show sources
- Arista patches VeloCloud Orchestrator zero-day exploited in attacks — www.bleepingcomputer.com — 28.07.2026 01:49
- Arista patches VeloCloud Orchestrator zero-day exploited in attacks — www.bleepingcomputer.com — 28.07.2026 01:49
- Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw — thehackernews.com — 28.07.2026 07:43