Arista has disclosed and patched CVE-2026-16812, a maximum-severity OS command injection flaw in VeloCloud Orchestrator (VCO) On-Prem that is being actively exploited in the wild. The vulnerability lets a remote, unauthenticated attacker with network access to the VCO web interface reach privileged internal functionality that was intended only for internal use, potentially compromising the confidentiality, integrity, and availability of the orchestrator and the data it manages. The issue is tracked as CWE-78 and carries a CVSS 3.1 score reflecting complete impact across all three security pillars.
Affected releases include 5.2.x before 5.2.3.14, 6.1.x before 6.1.3.4, 6.4.x before 6.4.2.4, and 7.0.x before 7.0.0.1. Arista said its Hosted and Dedicated VCO deployments were patched before public disclosure and are not affected, but warned that patching alone may not be enough if an instance was already compromised because attackers could also gain access to managed VeloCloud Edge devices. CISA has added the flaw to its Known Exploited Vulnerabilities catalog and directed U.S. federal civilian agencies to remediate it by July 30, 2026, while Arista has published indicators of compromise to support incident response.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
CISA added CVE-2026-16812 to its Known Exploited Vulnerabilities catalog, reflecting active exploitation. The reference also says federal civilian executive branch agencies were ordered to mitigate the issue by July 30, 2026.
Alongside its disclosure, Arista published indicators of compromise for CVE-2026-16812 and warned that patching alone may not fully remediate already-breached VCO instances. The company said attackers could also gain access to managed VeloCloud Edge devices after compromise.
Arista disclosed and patched CVE-2026-16812, a maximum-severity unauthenticated OS command injection flaw affecting on-premises VeloCloud Orchestrator deployments. The company said the vulnerability was being actively exploited in the wild and published affected version ranges.
Arista stated that VeloCloud Orchestrator Hosted and Dedicated versions were patched before the public notice for CVE-2026-16812 was published. The references do not provide a specific date for when those patches were applied.
Fortinet disclosed an information exposure vulnerability in FortiOS SSL-VPN that lets an unauthenticated attacker bypass a prior patch for the symbolic link persistence mechanism using crafted HTTP requests, but only after a device was already compromised and read-only filesystem access was obtained. The company listed affected FortiOS branches, provided fixed versions and upgrade guidance, and said a virtual patch named FG-VD-60389.0day was available in FMWP database update 26.033.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
17 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecyber.gc.ca
Open sourcecybersecuritynews.com
Open sourcesecurityweek.com
Open sourcearista.com
Open sourcefortiguard.fortinet.com
Open sourcesdxcentral.com
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.