CVE-2026-16812
Published Jul 27, 2026
Last updated 7 hours ago
AI description
CVE-2026-16812 is an OS command injection vulnerability found in Arista Networks VeloCloud Orchestrator (VCO) On-Prem. This flaw allows a remote attacker to execute operating system commands on the VCO host. The vulnerable functionality was originally intended for internal use only but remained remotely accessible. Successful exploitation of CVE-2026-16812 can lead to a compromise of the confidentiality, integrity, and availability of the orchestrator and the data it manages. This vulnerability does not require authentication for exploitation and has been actively exploited in the wild.
- Description
- VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. This functionality was intended to be for internal use only and is not intended to be remotely accessible. Hosted and Dedicated versions of VCO have already been patched in advance of this notice going out. This issue was discovered externally and is known to be actively exploited.
- Source
- psirt@arista.com
- NVD status
- Analyzed
- Products
- velocloud_orchestrator
CVSS 4.0
- Type
- Secondary
- Base score
- 10
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:X/R:X/V:X/RE:X/U:X
- Severity
- CRITICAL
CVSS 3.1
- Type
- Secondary
- Base score
- 10
- Impact score
- 6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
Data from CISA
- Vulnerability name
- Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability
- Exploit added on
- Jul 27, 2026
- Exploit action due
- Jul 30, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- psirt@arista.com
- CWE-78
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
15
🛡️ ExploitGrid Daily Threat Digest Top Vulnerabilities (CVEs) of the day CVE-2026-11756 CVE-2026-16812 CVE-2026-48030 CVE-2026-15014 CVE-2026-51303 ..🧵👇
@exploitgrid
28 Jul 2026
22 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
CISA adds CVE-2026-16812 in Arista VeloCloud Orchestrator and CVE-2025-68686 in FortiOS to its KEV catalog after confirming active exploitation.
@WorldCyberNewsX
28 Jul 2026
7 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🛡️ CYBER BULLETIN | 28/07/2026 Three relevant updates for today: 1. CISA adds two actively exploited vulnerabilities to the KEV catalog CISA has added a maximum-severity OS command injection in Arista VeloCloud Orchestrator (CVE-2026-16812, CVSS 10.0) and a Fortinet FortiO
@FrontieraTechIT
28 Jul 2026
40 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
⚠️ CVE of the week — CVE-2026-16812 (CVSS 10.0) · NVD/NIST 🔥 CISA KEV 💣 Exploit available https://t.co/wv1FPBxGYq 📬 Weekly recap → https://t.co/AnIOZKlL4u #cybersecurity #cve #vulnmanagement #kaitanid https://t.co/YQxfQwpr8V
@KaitanSecurity
28 Jul 2026
39 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
❗️GoogleがClaude AIの共有チャットをインデックス、一時的に検索結果に表示 🚨FortiOS、VeloCloud Orchestratorの脆弱性が攻撃で悪用される:米CISAがKEVカタログに追加(CVE-2025-68686、CVE-2026-16812) 〜サイバーアラー
@MachinaRecord
28 Jul 2026
177 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
CISAが既知の悪用された脆弱性2件をカタログに追加 CISA Adds Two Known Exploited Vulnerabilities to Catalog #CISA (Jul 27) CVE-2025-68686 Fortinet FortiOSにおける機密情報の不正アクセス脆弱性 CVE-2026-16812 Arista VeloCloud Orchestrator オ
@foxbook
28 Jul 2026
346 Impressions
0 Retweets
1 Like
1 Bookmark
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2025-68686 & CVE-2026-16812: CISA KEV Alert — FortiOS and VeloCloud Critica… "CISA has added two critical vulnerabilities to its Known Exploited Vulnerabilities (KEV)…" 🔗 https://t.co/wp10iYMnJQ #CyberSecurity #ThreatIntel #cve #zeroday #p
@SecurityAr58409
28 Jul 2026
53 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2026-16812: Arista VeloCloud Orchestrator — Active Exploitation Detection &… "On July 27, 2026, CISA added CVE-2026-16812 to the Known Exploited Vulnerabilities…" 🔗 https://t.co/8fSuo23CwB #CyberSecurity #ThreatIntel #cve202616812 #critica
@SecurityAr58409
28 Jul 2026
38 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CISA has added two actively exploited flaws to its KEV catalogue: • CVE-2026-16812 — Arista VeloCloud Orchestrator command injection • CVE-2025-68686 — FortiOS SSL-VPN vulnerability Treat both as emergency patch priorities. #CISA #CVE #BlueTeam Source: CISA, 27 Ju
@XQOPTRX
28 Jul 2026
15 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
米当局、「FortiOS」「VeloCloud Orchestrator」の脆弱性悪用を確認:Security NEXT https://t.co/Qj5ET5gu67 "CISAは現地時間2026年7月27日、「悪用が確認された脆弱性カタログ(KEV)」へ2件の脆弱性「CVE-2026-16812」「CVE-2025-68686」
@catnap707
27 Jul 2026
154 Impressions
0 Retweets
1 Like
1 Bookmark
0 Replies
0 Quotes
米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに、FortiOSのCVE-2025-68686とアリスタ社VeloCloud Orchestratorオンプレミス版のCVE-2026-16812を追加。対処期限はFortiOSが8/10、VeloClou
@__kokumoto
27 Jul 2026
1018 Impressions
0 Retweets
6 Likes
2 Bookmarks
2 Replies
0 Quotes
CISA KEV additions on July 27 flag two known exploited vulnerabilities: Arista VeloCloud CVE-2026-16812 and FortiOS CVE-2025-68686. Patch both now. #CISA #KEV #Arista #VeloCloud #Fortinet #FortiOS #CVE #ExploitedInTheWild #Cybersecurity https://t.co/y0zA64sZdu
@Daily_CyberSec
27 Jul 2026
372 Impressions
0 Retweets
1 Like
1 Bookmark
0 Replies
0 Quotes
🛡️ CYBER BULLETIN | 27/07/2026 Today's updates: 1. Critical Arista VeloCloud Orchestrator flaw added to CISA KEV Catalog CISA has added CVE-2026-16812 (OS command injection, CVSS 10.0) in Arista VeloCloud Orchestrator On-Prem to the Known Exploited Vulnerabilities Catalog
@FrontieraTechIT
27 Jul 2026
34 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
🛡️We added Fortinet FortiOS vulnerability CVE-2025-68686 and Arista Networks VeloCloud Orchestrator On-Prem CVE-2026-16812 to our KEV Catalog. Visit https://t.co/2EEdX3edvs & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https://t.co/QV
@CISACyber
27 Jul 2026
7842 Impressions
19 Retweets
31 Likes
8 Bookmarks
0 Replies
0 Quotes
#ExploitGrid Daily Threat Digest Top #Vulnerabilities (CVEs) of the day CVE-2026-16812 CVE-2026-12394 CVE-2026-13714 CVE-2026-63077 CVE-2026-66395 ..🧵👇
@exploitgrid
27 Jul 2026
46 Impressions
1 Retweet
0 Likes
0 Bookmarks
1 Reply
0 Quotes
🚨*CVE* CVE-2026-16812 VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO … https://t.co/6jVG0mx5zt ----- Traducción: CVE-2026-16812 Vel… https://t.co/utmtNg
@infoflowcloud
27 Jul 2026
28 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:arista:velocloud_orchestrator:*:*:*:*:*:*:*:*",
"matchCriteriaId": "F93AF860-FDF1-4061-813C-364DA582B642",
"versionEndExcluding": "5.2.3.14",
"versionStartIncluding": "5.2.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:arista:velocloud_orchestrator:*:*:*:*:*:*:*:*",
"matchCriteriaId": "AD5222D5-45E4-43F9-852C-898D26F8FCDF",
"versionEndExcluding": "6.1.3.4",
"versionStartIncluding": "6.1.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:arista:velocloud_orchestrator:*:*:*:*:*:*:*:*",
"matchCriteriaId": "C099915D-2F35-4A87-8154-82985B5DA811",
"versionEndExcluding": "6.4.2.4",
"versionStartIncluding": "6.4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:arista:velocloud_orchestrator:7.0.0:*:*:*:*:*:*:*",
"matchCriteriaId": "40BC6B76-2FB0-4D62-9F46-B36A863BDCE9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]