Skip to content
The Nexus
SECURITYJul 28 · 04:43 UTCTHE HACKER NEWS[email protected] (The Hacker News)

Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw

A maximum-severity command injection vulnerability (CVE-2026-16812) in on-premises versions of Arista VeloCloud Orchestrator is being actively exploited, allowing arbitrary code execution. The flaw, rated with a CVSS score of 10.0, enables attackers to execute operating system commands through the affected system.

Nexus surfaces and summarizes. The full story lives at the source.

Mentioned
Spot something wrong with this article?Report a problem →
Forward this
Related Signal

Adjacent reporting