CVE Record
[ CRITICAL ] CVE-2026-16812
Arista VeloCloud Orchestrator OS Command Injection
CVSS 10.0 critical. Remote attackers can inject OS commands into Arista VeloCloud Orchestrator On-Prem, compromising the SD-WAN management plane.
- Vendor
- Arista
- Product
- VeloCloud Orchestrator On-Prem
- CVSS
- 10.0
- EPSS (exploit probability)
- N/A
- Status
- kev
- Published
OS command injection in Arista VeloCloud Orchestrator On-Prem. A remote attacker can access privileged internal functionality and fully compromise the VCO host — impacting confidentiality, integrity, and availability of the orchestrator and all data it manages.
CISA added CVE-2026-16812 to the Known Exploited Vulnerabilities catalog on July 27, 2026. Active exploitation confirmed. Federal agencies are under BOD 26-04 remediation deadlines.
Patch: consult Arista SA-0144 for fixed versions. NVD entry.
