[KEV] CVE-2026-16812 -- CVSS 0.0 Vulnerability Briefing
[KEV] CVE-2026-16812 | CVSS 0.0 (Low) | Exploit: Operational
What Is It
CVE-2026-16812 is an OS command injection vulnerability in Arista VeloCloud Orchestrator On-Prem that may be reachable remotely through the orchestrator's exposed functionality.
Technical Detail
The flaw may allow a remote attacker to inject operating system commands and access privileged internal VeloCloud Orchestrator functionality. Successful exploitation could enable command execution on, or otherwise materially affect, the VCO host. An attacker may compromise the confidentiality, integrity, and availability of the orchestrator and the data it manages; authentication requirements and the specific vulnerable input path have not been provided.
Exploitation Status
Exploit maturity is assessed as Operational, meaning exploitation capability is usable in real-world intrusions rather than limited to a proof of concept. CISA has confirmed active exploitation in the wild. CISA added this vulnerability to the Known Exploited Vulnerabilities Catalog on July 27, 2026.
Who Is Targeting This
No specific threat actor attribution at this time.
What To Do
Treat this as an urgent remediation priority. Apply Arista's security update or other vendor-provided remediation for affected VeloCloud Orchestrator On-Prem deployments as soon as available; affected versions and a specific patch identifier were not provided. Restrict access to VCO management and administrative interfaces to authorized management networks, VPN-connected administrators, and allowlisted source addresses, and do not expose those interfaces directly to the public internet unless operationally required.
Monitor VCO and host logs for unexpected command execution, unusual child processes spawned by VCO services, suspicious administrative actions, and anomalous outbound connections from the orchestrator host. Review affected systems for signs of compromise and rotate administrator credentials, API credentials, and other secrets accessible to the orchestrator if suspicious activity is identified. Under CISA's KEV remediation requirements, federal civilian executive branch agencies should patch by the CISA-specified due date or apply mitigations; the supplied KEV data does not include the remediation due date.