SECURITYTHE HACKER NEWS
Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
A maximum-severity command injection vulnerability (CVE-2026-16812) in on-premises versions of Arista VeloCloud Orchestrator is being actively exploited, allowing arbitrary code execution. The flaw, rated with a CVSS score of 10.0, enables attackers to execute operating system commands through the affected system.
Mentioned
Related Signal
Adjacent reporting
- Arista patches VeloCloud Orchestrator zero-day exploited in attacks
- 9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros
- Max severity Flowise RCE vulnerability now exploited in attacks
- PAN-OS RCE Exploit Under Active Use Enabling Root Access and Espionage
- Researchers Discover Critical GitHub CVE-2026-3854 RCE Flaw Exploitable via Single Git Push