CVE-2026-16812

Published Jul 27, 2026

Last updated 7 hours ago

Exploit knownCVSS critical 10.0
VeloCloud Orchestrator
VCO

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-16812 is an OS command injection vulnerability found in Arista Networks VeloCloud Orchestrator (VCO) On-Prem. This flaw allows a remote attacker to execute operating system commands on the VCO host. The vulnerable functionality was originally intended for internal use only but remained remotely accessible. Successful exploitation of CVE-2026-16812 can lead to a compromise of the confidentiality, integrity, and availability of the orchestrator and the data it manages. This vulnerability does not require authentication for exploitation and has been actively exploited in the wild.

Description
VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. This functionality was intended to be for internal use only and is not intended to be remotely accessible. Hosted and Dedicated versions of VCO have already been patched in advance of this notice going out. This issue was discovered externally and is known to be actively exploited.
Source
psirt@arista.com
NVD status
Analyzed
Products
velocloud_orchestrator

Risk scores

CVSS 4.0

Type
Secondary
Base score
10
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

CVSS 3.1

Type
Secondary
Base score
10
Impact score
6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability
Exploit added on
Jul 27, 2026
Exploit action due
Jul 30, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

psirt@arista.com
CWE-78

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

15

  1. 🛡️ ExploitGrid Daily Threat Digest Top Vulnerabilities (CVEs) of the day CVE-2026-11756 CVE-2026-16812 CVE-2026-48030 CVE-2026-15014 CVE-2026-51303 ..🧵👇

    @exploitgrid

    28 Jul 2026

    22 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  2. CISA adds CVE-2026-16812 in Arista VeloCloud Orchestrator and CVE-2025-68686 in FortiOS to its KEV catalog after confirming active exploitation.

    @WorldCyberNewsX

    28 Jul 2026

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🛡️ CYBER BULLETIN | 28/07/2026 Three relevant updates for today: 1. CISA adds two actively exploited vulnerabilities to the KEV catalog CISA has added a maximum-severity OS command injection in Arista VeloCloud Orchestrator (CVE-2026-16812, CVSS 10.0) and a Fortinet FortiO

    @FrontieraTechIT

    28 Jul 2026

    40 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  4. ⚠️ CVE of the week — CVE-2026-16812 (CVSS 10.0) · NVD/NIST 🔥 CISA KEV 💣 Exploit available https://t.co/wv1FPBxGYq 📬 Weekly recap → https://t.co/AnIOZKlL4u #cybersecurity #cve #vulnmanagement #kaitanid https://t.co/YQxfQwpr8V

    @KaitanSecurity

    28 Jul 2026

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. ❗️GoogleがClaude AIの共有チャットをインデックス、一時的に検索結果に表示 🚨FortiOS、VeloCloud Orchestratorの脆弱性が攻撃で悪用される:米CISAがKEVカタログに追加(CVE-2025-68686、CVE-2026-16812) 〜サイバーアラー

    @MachinaRecord

    28 Jul 2026

    177 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  6. CISAが既知の悪用された脆弱性2件をカタログに追加 CISA Adds Two Known Exploited Vulnerabilities to Catalog #CISA (Jul 27) CVE-2025-68686 Fortinet FortiOSにおける機密情報の不正アクセス脆弱性 CVE-2026-16812 Arista VeloCloud Orchestrator オ

    @foxbook

    28 Jul 2026

    346 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  7. 🔒 #CyberSecurity CVE-2025-68686 & CVE-2026-16812: CISA KEV Alert — FortiOS and VeloCloud Critica… "CISA has added two critical vulnerabilities to its Known Exploited Vulnerabilities (KEV)…" 🔗 https://t.co/wp10iYMnJQ #CyberSecurity #ThreatIntel #cve #zeroday #p

    @SecurityAr58409

    28 Jul 2026

    53 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 🔒 #CyberSecurity CVE-2026-16812: Arista VeloCloud Orchestrator — Active Exploitation Detection &… "On July 27, 2026, CISA added CVE-2026-16812 to the Known Exploited Vulnerabilities…" 🔗 https://t.co/8fSuo23CwB #CyberSecurity #ThreatIntel #cve202616812 #critica

    @SecurityAr58409

    28 Jul 2026

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. 🚨 CISA has added two actively exploited flaws to its KEV catalogue: • CVE-2026-16812 — Arista VeloCloud Orchestrator command injection • CVE-2025-68686 — FortiOS SSL-VPN vulnerability Treat both as emergency patch priorities. #CISA #CVE #BlueTeam Source: CISA, 27 Ju

    @XQOPTRX

    28 Jul 2026

    15 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. 米当局、「FortiOS」「VeloCloud Orchestrator」の脆弱性悪用を確認:Security NEXT https://t.co/Qj5ET5gu67 "CISAは現地時間2026年7月27日、「悪用が確認された脆弱性カタログ(KEV)」へ2件の脆弱性「CVE-2026-16812」「CVE-2025-68686」

    @catnap707

    27 Jul 2026

    154 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  11. 米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに、FortiOSのCVE-2025-68686とアリスタ社VeloCloud Orchestratorオンプレミス版のCVE-2026-16812を追加。対処期限はFortiOSが8/10、VeloClou

    @__kokumoto

    27 Jul 2026

    1018 Impressions

    0 Retweets

    6 Likes

    2 Bookmarks

    2 Replies

    0 Quotes

  12. CISA KEV additions on July 27 flag two known exploited vulnerabilities: Arista VeloCloud CVE-2026-16812 and FortiOS CVE-2025-68686. Patch both now. #CISA #KEV #Arista #VeloCloud #Fortinet #FortiOS #CVE #ExploitedInTheWild #Cybersecurity https://t.co/y0zA64sZdu

    @Daily_CyberSec

    27 Jul 2026

    372 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  13. 🛡️ CYBER BULLETIN | 27/07/2026 Today's updates: 1. Critical Arista VeloCloud Orchestrator flaw added to CISA KEV Catalog CISA has added CVE-2026-16812 (OS command injection, CVSS 10.0) in Arista VeloCloud Orchestrator On-Prem to the Known Exploited Vulnerabilities Catalog

    @FrontieraTechIT

    27 Jul 2026

    34 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  14. 🛡️We added Fortinet FortiOS vulnerability CVE-2025-68686 and Arista Networks VeloCloud Orchestrator On-Prem CVE-2026-16812 to our KEV Catalog. Visit https://t.co/2EEdX3edvs & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https://t.co/QV

    @CISACyber

    27 Jul 2026

    7842 Impressions

    19 Retweets

    31 Likes

    8 Bookmarks

    0 Replies

    0 Quotes

  15. #ExploitGrid Daily Threat Digest Top #Vulnerabilities (CVEs) of the day CVE-2026-16812 CVE-2026-12394 CVE-2026-13714 CVE-2026-63077 CVE-2026-66395 ..🧵👇

    @exploitgrid

    27 Jul 2026

    46 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  16. 🚨*CVE* CVE-2026-16812 VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO … https://t.co/6jVG0mx5zt ----- Traducción: CVE-2026-16812 Vel… https://t.co/utmtNg

    @infoflowcloud

    27 Jul 2026

    28 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations