Breaking
SecurityConfirmed

CISA Adds Arista VeloCloud to KEV List

A critical OS command injection vulnerability in Arista VeloCloud Orchestrator is now confirmed to be exploited in the wild.

··1 month ago·1 min read
person in black long sleeve shirt using macbook pro
Photo by Towfiqu barbhuiya on Unsplash

The Cybersecurity and Infrastructure Security Agency (CISA) has officially added CVE-2026-16812 to its Known Exploited Vulnerabilities (KEV) catalog. This inclusion signals that the agency has confirmed active, real-world exploitation of the security flaw affecting the Arista VeloCloud Orchestrator On-Prem software.

Understanding the Orchestrator Flaw

The vulnerability, identified as an OS command injection, allows a remote attacker to gain unauthorized access to privileged internal functions. By leveraging this weakness, an adversary can directly impact the VCO host, potentially compromising the confidentiality, integrity, and availability of the orchestrator itself and the sensitive data it manages.

Federal Remediation Mandates

Due to the active exploitation, CISA has issued strict remediation requirements for federal agencies. The agency has set a firm remediation due date of 2026-07-30. Stakeholders are directed to follow vendor instructions to apply necessary mitigations and ensure full compliance with BOD 26-04, which outlines procedures for prioritizing security updates based on identified risks.

  • CVE Identifier: CVE-2026-16812
  • CISA KEV Addition Date: 2026-07-27
  • Remediation Deadline: 2026-07-30
  • Weakness Classification: CWE-78

Operational Security Requirements

Beyond standard patching, the agency requires compliance with specific Forensics Triage Requirements. Organizations are responsible for performing a thorough evaluation of the internet exposure of their assets. If official mitigations cannot be implemented, agencies are instructed to follow established guidance for cloud services or, if necessary, discontinue the use of the product until a secure configuration is confirmed.

Implications for Infrastructure

The addition of this vulnerability to the KEV catalog indicates that the threat is no longer theoretical, but an active concern for network administrators and security teams. For organizations managing Arista VeloCloud infrastructure, this development suggests that any delay in applying mitigations could leave the orchestrator and its managed network segments open to unauthorized command execution. Following the established BOD 26-04 guidelines is the primary mechanism for maintaining the security posture of these systems against potential remote exploitation.

#cve-2026-16812#arista#command injection#cisa#vulnerability

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories