Dossier
CVE-2026-16812
Coverage of CVE-2026-16812 in the Nexus archive.
- Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
A maximum-severity command injection vulnerability (CVE-2026-16812) in on-premises versions of Arista VeloCloud Orchestrator is being actively exploited, allowing arbitrary code execution. The flaw, rated with a CVSS score of 10.0, enables attackers to execute operating system commands through the affected system.