## Overview
CISA added CVE-2026-16812 to its Known Exploited Vulnerabilities (KEV) catalog on July 27, 2026. This vulnerability affects the Arista VeloCloud Orchestrator (VCO) on-premises version. It allows remote attackers to exploit an OS command injection flaw. The vulnerability grants access to privileged internal functionality, which was never intended for remote access.
## Technical Details
The vulnerability exists within the VeloCloud Orchestrator's design. It exposes internal functions that should only be accessible locally. Attackers can exploit this flaw to execute arbitrary commands on the VCO host. This can lead to unauthorized access and manipulation of the orchestrator’s data and services. The vulnerability has a CVSS score of 10.0, indicating critical severity.
## Impact
Successful exploitation of CVE-2026-16812 can compromise the confidentiality, integrity, and availability of the VCO and its managed data. This puts organizations at risk of data breaches and operational disruptions. The vulnerability is known to be actively exploited, raising urgency for mitigation efforts.
## Mitigation
Arista has already patched the Hosted and Dedicated versions of VCO prior to the KEV notice. Organizations using affected versions should apply the latest patches immediately. It is crucial to review access controls and ensure that internal functionalities are not exposed to the internet. Regular vulnerability assessments can help identify and mitigate similar risks in the future.
CSURFACE Threat Sensor