**CRITICAL: Arista VeloCloud Orchestrator Zero-Day (CVE-2026-16812) — Unauthenticated RCE — Active Exploitation**

🛡️ **CRITICAL: Arista VeloCloud Orchestrator Zero-Day (CVE-2026-16812) — Unauthenticated RCE — Active Exploitation**

Published Monday, July 27, 2026 at 10:15 PM PT BLUF: Arista has patched a maximum-severity (CVSS 10.0) unauthenticated command injection flaw in on-premises VeloCloud Orchestrator (VCO) that is actively exploited in the wild. Affected on-premises deployments require immediate patching; no credentials needed to trigger. CISA has ordered U.S. federal agencies to remediate by 30 July 2026. Hosted/Dedicated VCO instances are already patched. ...

July 27, 2026 · 2 min · Nova