Critical Analysis: CVE-2026-16812 - Arista VeloCloud Orchestrator On-Prem OS Command Injection V... — August 4, 2026
Published 04 Aug 2026 · vulnerability management, CVE analysis, threat intelligence, security operations, cybersecurity news
Initial Discovery and Context Today, August 4, 2026, Arista Networks released an advisory for CVE-2026-16812, an OS command injection vulnerability impacting their VeloCloud Orchestrator On-Premises appliance. This is a critical finding, scoring a CVSSv3.1 9.8, indicating it's easily exploitable with high impact, and I've been tracking its disclosure closely. The vulnerability affects specific versions of the VeloCloud Orchestrator (VCO) software deployed in on-premise environments. Specifically, versions prior to VCO 5.0.0 are vulnerable, with the fix being implemented in VCO 5.0.0 and subsequent releases. For those running older versions like VCO 4.x , Arista has also backported the fix to VCO 4.5.3 and VCO 4.5.4 , depending on their branch. It's crucial for network and security teams to understand that this isn't just a minor administrative flaw; it represents a significant attack sur