EXPOSURES › CVE-2026-16812
CVE-2026-16812
HIGH ⌖ ON CISA KEV · EXPLOITEDArista's VeloCloud Orchestrator has a command injection vulnerability actively exploited in the wild, potentially granting attackers privileged access to internal systems and data managed by the orchestrator.
A command injection vulnerability in Arista VeloCloud Orchestrator allows remote attackers to execute arbitrary commands, potentially compromising the confidentiality, integrity, and availability of the system and its managed data. DIB organizations using this product must prioritize patching to prevent unauthorized access and data breaches, impacting CMMC compliance.
Shame score — The active exploitation of a command injection vulnerability indicates a significant failure in secure coding practices and a potential for widespread compromise.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.