๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2026-16812: Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability
Summary
Arista VeloCloud Orchestrator On-Prem has an OS command injection vulnerability (a flaw that lets attackers run unauthorized commands on a system) that could allow remote attackers to gain privileged access and compromise the security and data of the orchestrator. This vulnerability is actively being exploited by attackers in the wild.
Solution / Mitigation
Apply mitigations in accordance with vendor instructions from Arista's security advisory at https://www.arista.com/en/support/advisories-notices/security-advisory/24364-security-advisory-0144, ensuring compliance with CISA's BOD 26-04 guidance. If mitigations are unavailable for cloud services, discontinue use of the product. Organizations must evaluate each system's internet exposure and follow BOD 26-04 patching guidelines by the due date of 2026-07-30.
Vulnerability Details
EPSS: 0.0%
Yes
๐ฅ Actively Exploited
July 26, 2026
Classification
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-16812
First tracked: July 27, 2026 at 08:01 PM
Classified by LLM (prompt v3) ยท confidence: 95%