Exploited in the wild VeloCloud Orchestrator zero-day Arista rce
Arista patches VeloCloud Orchestrator zero-day exploited in attacks
CVE Tools coverage
Arista has released a critical patch for a zero-day vulnerability in VeloCloud Orchestrator that is currently being exploited in real-world attacks. The flaw, identified as CVE-2026-16812, allows remote attackers to execute arbitrary commands without authentication, potentially leading to full system compromise. This high-severity issue affects several on-premises versions of the software, including those prior to 5.2.3.14, 6.1.3.4, and 6.4.2.4. Arista confirmed the vulnerability was discovered externally and is actively under attack, though details about the threat actors remain undisclosed. CISA has added the flaw to its Known Exploited Vulnerabilities list and mandated mitigation by July 30, 2026.