Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks.
The vulnerability, tracked as CVE-2026–16812, is an unauthenticated OS command injection flaw with severity scores of 10.0, the maximum score that can be given to flaws.
VeloCloud Orchestrator, also known as VCO, is a centralized management platform used to configure, monitor, and manage VeloCloud SD-WAN deployments and associated edge devices.
