vulnerability Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day Arista Networks has released patches for a critical zero-day vulnerability in its VeloCloud Orchestrator, which has been actively exploited in the wild. The flaw allows remote access to privileged functionality, and no special configuration is needed for exploitation. CISA has added the vulnerability to its KEV catalog… SecurityWeek · Jul 28, 2026 Critical CVE-2026-16812CVE-2025-68686CVE-2022-42475zero-daypatchvulnerability
vulnerability Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw A maximum-severity command injection vulnerability (CVE-2026-16812) in Arista VeloCloud Orchestrator (VCO) has been actively exploited in the wild, allowing remote code execution and potential access to VeloCloud Edge de… The Hacker News · Jul 28, 2026 Critical CVE-2026-16812CVE-2025-68686CVE-2026-16723command injectionvcocisa