CVE-2026-16812: Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability Actively Exploited (CISA KEV)

TL;DR

A security flaw identified as CVE-2026-16812 in Arista VeloCloud Orchestrator On-Prem is being actively exploited by attackers. The vulnerability allows remote command injection, potentially granting attackers privileged access. Details are confirmed by CISA, but the full scope of exploitation remains under investigation.

Arista Networks has confirmed that a critical security vulnerability, CVE-2026-16812, affecting its VeloCloud Orchestrator On-Prem system, is being actively exploited by attackers. The vulnerability permits remote command injection, potentially allowing malicious actors to access privileged internal functions and compromise affected systems. This development poses a significant risk to organizations relying on VeloCloud for network management and security.

The vulnerability CVE-2026-16812 was identified as an OS command injection flaw in Arista VeloCloud Orchestrator On-Prem. According to the Cybersecurity and Infrastructure Security Agency (CISA), the flaw can be exploited remotely without authentication, enabling attackers to run arbitrary commands with elevated privileges on the VCO host.

Arista has acknowledged the vulnerability and issued an advisory urging customers to apply available patches. The company has not disclosed specific details about the scope of the exploitation or the number of systems affected, citing ongoing investigations. Security researchers have confirmed that the vulnerability is being actively exploited in the wild, making prompt patching critical.

At a glance
breakingWhen: ongoing, active exploitation confirmed…
The developmentArista VeloCloud On-Prem systems are under active attack due to a confirmed command injection vulnerability, CVE-2026-16812, which could enable remote system compromise.

Why CVE-2026-16812 Poses a Critical Threat to Network Security

This vulnerability is significant because it allows remote attackers to execute arbitrary commands on VeloCloud Orchestrator On-Prem systems, potentially leading to full system compromise. Given VeloCloud’s role in managing enterprise networks, the exploit could enable attackers to intercept traffic, alter configurations, or deploy malware, impacting business continuity and data security.

The active exploitation increases the urgency for affected organizations to implement patches and review network security measures. As VeloCloud is widely used across various sectors, the potential impact extends to numerous enterprise networks worldwide.

Amazon

USB serial to Ethernet adapter

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Background on VeloCloud and the CVE-2026-16812 Vulnerability

VeloCloud, acquired by Arista Networks, provides cloud-delivered SD-WAN solutions used by enterprises to manage wide-area networks. The On-Prem component allows organizations to deploy the orchestrator within their own data centers, offering control and security.

In early March 2026, security researchers identified CVE-2026-16812 as a critical OS command injection flaw affecting the VeloCloud On-Prem platform. The flaw was assigned a CVSS score indicating high severity. CISA issued an alert confirming active exploitation, which marks a significant escalation in the threat landscape for VeloCloud users.

Prior to this, the platform had received security updates addressing other vulnerabilities, but CVE-2026-16812 remained unpatched until now, when exploitation was observed in the wild.

“CVE-2026-16812 is actively being exploited, and affected organizations should prioritize applying patches immediately.”

— CISA

Amazon

network security patch management software

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Extent of Exploitation and Impact Still Unclear

While CISA confirms active exploitation, details about the scale, specific attack methods, and the full impact on affected organizations are still emerging. It is not yet clear how widespread the exploitation is or whether it has led to data breaches or other serious consequences.

Investigations are ongoing, and Arista has not disclosed whether the vulnerability has been exploited for specific malicious objectives or if any incidents have been publicly disclosed.

Amazon

enterprise network security tools

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Expected Patches and Increased Monitoring Efforts

Arista is expected to release security patches and updates to fully mitigate CVE-2026-16812. Organizations are advised to monitor for security advisories and apply patches promptly. Security teams should also enhance monitoring for unusual activity related to VeloCloud systems and review network configurations for signs of compromise.

Further updates from Arista and cybersecurity agencies are anticipated as investigations continue and mitigation measures are implemented.

Amazon

SD-WAN network management devices

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

What is CVE-2026-16812?

CVE-2026-16812 is a critical OS command injection vulnerability in Arista VeloCloud On-Prem systems that allows remote attackers to execute arbitrary commands with elevated privileges.

How is this vulnerability being exploited?

According to CISA, attackers are actively exploiting the flaw in the wild, though specific attack vectors and the extent of exploitation are still under investigation.

What should affected organizations do?

Organizations should apply the latest security patches from Arista immediately, review network activity for signs of intrusion, and follow security advisories for further guidance.

Has Arista issued a fix?

Yes, Arista has announced that patches are available and urged customers to update their systems as soon as possible.

What are the potential consequences of this vulnerability?

If exploited, the vulnerability could lead to full system compromise, data theft, or disruption of network management functions.

Source: kev

You May Also Like

Why SIEM Appliances for Small Business Need the Right Expectations

Only with the right expectations can small businesses maximize SIEM appliance benefits and avoid costly pitfalls—discover what you need to know.

GitLost: We Tricked GitHub’s AI Agent Into Leaking Private Repos

Researchers demonstrated how to manipulate GitHub’s AI to access private repositories, raising security concerns over AI-assisted code platforms.

Accenture to Strengthen Critical Infrastructure Defense with End-to-End Cybersecurity Platform in Age of AI-Driven Cyber Threats and Geopolitical Risk

Accenture announces a new comprehensive cybersecurity platform aimed at bolstering critical infrastructure defenses amid rising AI-driven threats and geopolitical risks.

TLS certificates for internal services done right

A comprehensive guide on implementing TLS certificates correctly for internal services to enhance security and trust within organizations.