🔴 Critical | Source: The Hacker News
A critical command injection vulnerability (CVE-2026-16812, CVSS 10.0) in on-premises Arista VeloCloud Orchestrator is being actively exploited in the wild, allowing attackers to execute arbitrary operating system commands. VeloCloud Orchestrator is a SD-WAN management platform widely used to control network connectivity across enterprise and cloud environments. Active exploitation means unpatched deployments are at immediate risk of full system compromise.
Security Architect’s Take: Prioritise emergency patching of all on-premises VeloCloud Orchestrator instances immediately, and in the interim restrict management-plane access to trusted IP ranges via firewall rules or a jump host — do not expose the VCO admin interface directly to the internet.
Original advisory: Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw