CISA Adds Arista VeloCloud to KEV List
A critical OS command injection vulnerability in Arista VeloCloud Orchestrator is now confirmed to be exploited in the wild.
The Cybersecurity and Infrastructure Security Agency (CISA) has officially added CVE-2026-16812 to its Known Exploited Vulnerabilities (KEV) catalog. This inclusion signals that the agency has confirmed active, real-world exploitation of the security flaw affecting the Arista VeloCloud Orchestrator On-Prem software.
Understanding the Orchestrator Flaw
The vulnerability, identified as an OS command injection, allows a remote attacker to gain unauthorized access to privileged internal functions. By leveraging this weakness, an adversary can directly impact the VCO host, potentially compromising the confidentiality, integrity, and availability of the orchestrator itself and the sensitive data it manages.
Federal Remediation Mandates
Due to the active exploitation, CISA has issued strict remediation requirements for federal agencies. The agency has set a firm remediation due date of 2026-07-30. Stakeholders are directed to follow vendor instructions to apply necessary mitigations and ensure full compliance with BOD 26-04, which outlines procedures for prioritizing security updates based on identified risks.
- CVE Identifier: CVE-2026-16812
- CISA KEV Addition Date: 2026-07-27
- Remediation Deadline: 2026-07-30
- Weakness Classification: CWE-78
Operational Security Requirements
Beyond standard patching, the agency requires compliance with specific Forensics Triage Requirements. Organizations are responsible for performing a thorough evaluation of the internet exposure of their assets. If official mitigations cannot be implemented, agencies are instructed to follow established guidance for cloud services or, if necessary, discontinue the use of the product until a secure configuration is confirmed.
Implications for Infrastructure
The addition of this vulnerability to the KEV catalog indicates that the threat is no longer theoretical, but an active concern for network administrators and security teams. For organizations managing Arista VeloCloud infrastructure, this development suggests that any delay in applying mitigations could leave the orchestrator and its managed network segments open to unauthorized command execution. Following the established BOD 26-04 guidelines is the primary mechanism for maintaining the security posture of these systems against potential remote exploitation.
Sources
- CISA KEV Original source
Continue Reading
Check Point's Patch Gap Leaves VPN Flaws Exposed
Two 9.8-rated certificate flaws in Check Point gateways carry fixes that some customers say they cannot access.
Mandia's Amazon Board Seat and Its Logic
Cybersecurity veteran Kevin Mandia has joined Amazon's board, a move the company says reflects its commitment to security experience at all levels.
August M&A: Deals That Reshape Security
Thirty-three cybersecurity M&A deals were announced in August 2026, with AI, identity, and exposure management topping the shopping lists.