A critical command‑injection flaw (CVE‑2026‑16812) in Arista’s on‑prem VeloCloud Orchestrator has a perfect‑10 CVSS score and is currently being exploited in the wild, enabling attackers to execute arbitrary code on affected systems.

Key Takeaways

  • CVE‑2026‑16812 enables OS command injection.
  • All on‑premise VeloCloud Orchestrator deployments are affected.
  • Active exploitation observed; immediate patching required.

Vulnerability Details

The on‑premises version of Arista’s VeloCloud Orchestrator (VCO) contains an operating‑system command injection bug tracked as CVE‑2026‑16812. With a CVSS score of 10.0, the flaw allows attackers to run arbitrary shell commands, paving the way for full remote code execution.

Potential Impact

Successful exploitation can let threat actors steal data, deploy ransomware, or completely commandeer the network edge device, causing widespread service outages and financial loss.

Immediate Mitigation Steps

Arista urges customers to apply the latest security patch immediately. Organizations should also tighten firewall rules, block unauthorized outbound traffic, and enforce multi‑factor authentication (MFA) for all administrative access.

Why This Matters

BozokMedia analysis shows that a breach exploiting this flaw could compromise critical enterprise WAN‑edge infrastructure, leading to widespread service disruptions and financial loss.

"The risk of remote code execution through this flaw is comparable to the most severe ransomware attacks of the past decade."
Did You Know?: Arista acquired VeloCloud in 2020, turning it into a leading cloud‑managed networking solution.

Frequently Asked Questions

  1. Is this vulnerability limited to the cloud version? No, it specifically targets on‑premises VCO installations.
  2. Is a patch already available? Yes, Arista released an official security bulletin with the necessary update.