Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock
Unauthenticated command injection scores perfect 10 and may expose managed Edge devices
A critical flaw in Arista's VeloCloud Orchestrator has gone from zero to KEV in short order, with the networking giant confirming attackers are already exploiting it.
The vulnerability, tracked as CVE-2026-16812, carries a maximum CVSS score of 10.0 and affects VeloCloud Orchestrator On-Prem, the self-hosted version of the software that enterprises use to centrally manage VeloCloud software-defined wide area networks (SD-WANs) connecting branch offices, datacenters, and clouds environments.
According to Arista's security advisory, the flaw is an OS command injection vulnerability that allows an unauthenticated remote attacker to reach privileged internal functionality that was never meant to be exposed externally.
Worse, Arista says the on-premises orchestrator is exposed by default, with no configuration capable of removing that exposure entirely. Exploitation requires access to the web interface but no credentials. Until administrators can patch, Arista recommends restricting that...
Copyright of this story solely belongs to theregister.com. To see the full text click HERE