vulnerability Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw A maximum-severity command injection vulnerability (CVE-2026-16812) in Arista VeloCloud Orchestrator (VCO) has been actively exploited in the wild, allowing remote code execution and potential access to VeloCloud Edge devices. Arista has released patches, but due to active exploitation, agencies are required to apply t… The Hacker News · Jul 28, 2026 Critical CVE-2026-16812CVE-2025-68686CVE-2026-16723command injectionvcocisa