CVE-2026-16812 lets an unauthenticated attacker run OS commands on VeloCloud Orchestrator On-Prem by sending a crafted HTTP request. It scores 10.0, it was exploited as a zero-day, and CISA has added it to the KEV catalog.
Read the full story: Arista VeloCloud Zero-Day: CVSS 10, No Safe Config →
Transcript
Arista just patched a bug that scores a perfect ten out of ten. CVE-2026-16812 lets anyone send one crafted request to a VeloCloud Orchestrator and run commands with full privileges. No login, no session, nothing. Attackers were already using it before the fix shipped, which is what makes it a zero-day. Here's the part that should worry you more: the management interface is exposed by default, and there's no configuration that removes that exposure. The edges need to reach it to get their policy, so the attack surface is the product working as intended. CISA already added this to its known-exploited list. If you run VeloCloud Orchestrator on-prem, patch today, then rotate every credential it holds.