Dossier
Arista VeloCloud Orchestrator
Coverage of Arista VeloCloud Orchestrator in the Nexus archive.
- Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
A maximum-severity command injection vulnerability (CVE-2026-16812) in on-premises versions of Arista VeloCloud Orchestrator is being actively exploited, allowing arbitrary code execution. The flaw, rated with a CVSS score of 10.0, enables attackers to execute operating system commands through the affected system.