A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild.The vulnerability, tracked as CVE-2026-16812 (CVSS score: 10.0), is a case of operating system command injection that could pave the way for arbitrary code execution.”VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue
First seen on thehackernews.com
Jump to article: thehackernews.com/2026/07/attackers-exploit-arista-velocloud.html
![]()

