CVE-2026-16812
exploitation · critical · Evidence score 90
- Vendor
- Arista
- Affected software
- Arista VeloCloud Orchestrator
- Exploitation signal
- Listed in CISA Known Exploited Vulnerabilities
- EPSS
- 0.00884
Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.
Provenance
CISA Known Exploited Vulnerabilities
27 July 2026, 10:00 AM AEST