A critical command‑injection flaw (CVE‑2026‑16812) in Arista’s on‑prem VeloCloud Orchestrator has a perfect‑10 CVSS score and is currently being exploited in the wild, enabling attackers to execute arbitrary code on affected systems.
Key Takeaways
- CVE‑2026‑16812 enables OS command injection.
- All on‑premise VeloCloud Orchestrator deployments are affected.
- Active exploitation observed; immediate patching required.
Vulnerability Details
The on‑premises version of Arista’s VeloCloud Orchestrator (VCO) contains an operating‑system command injection bug tracked as CVE‑2026‑16812. With a CVSS score of 10.0, the flaw allows attackers to run arbitrary shell commands, paving the way for full remote code execution.
Potential Impact
Successful exploitation can let threat actors steal data, deploy ransomware, or completely commandeer the network edge device, causing widespread service outages and financial loss.
Immediate Mitigation Steps
Arista urges customers to apply the latest security patch immediately. Organizations should also tighten firewall rules, block unauthorized outbound traffic, and enforce multi‑factor authentication (MFA) for all administrative access.
Why This Matters
BozokMedia analysis shows that a breach exploiting this flaw could compromise critical enterprise WAN‑edge infrastructure, leading to widespread service disruptions and financial loss.
"The risk of remote code execution through this flaw is comparable to the most severe ransomware attacks of the past decade."
Frequently Asked Questions
- Is this vulnerability limited to the cloud version? No, it specifically targets on‑premises VCO installations.
- Is a patch already available? Yes, Arista released an official security bulletin with the necessary update.