A maximum-severity command injection vulnerability in on-premises versions of Arista VeloCloud Orchestrator (VCO) is being actively exploited. Tracked as CVE-2026-16812 with a CVSS score of 10.0, the flaw allows remote attackers to execute arbitrary code and access privileged internal functionality, potentially compromising the confidentiality, integrity, and availability of the orchestrator and its managed data.
Arista has addressed the issue in hosted and dedicated VCO versions. Affected on-premises releases include VCO 5.2.x before 5.2.3.14, 6.1.x before 6.1.3.4, 6.4.x before 6.4.2.4, and 7.0.x before 7.0.0.1. The company provided three IP addresses as indicators of compromise: 8.19.75.217, 206.72.242.124, and 206.72.242.162. Customers are urged to block these IPs, review logs, and apply patches immediately. If patching is not possible, restrict VCO web interface access to trusted networks and monitor for suspicious activity.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-16812 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch agencies to patch by July 30, 2026. Additionally, CISA added a medium-severity Fortinet FortiOS SSL-VPN flaw (CVE-2025-68686, CVSS 5.3) to the KEV catalog, citing active exploitation. Fortinet patched this in February 2026. Another critical unpatched vulnerability, CVE-2026-16723 (CVSS 9.0), affects Alibaba’s Fastjson library (versions 1.2.68 through 1.2.83) and allows remote code execution without user interaction. Developers are advised to enable SafeMode or switch to a non-impacted build.
CVEs: CVE-2026-16812, CVE-2025-68686, CVE-2026-16723, CVE-2026-50522
Companies: Arista, Fortinet, Alibaba
Products: VeloCloud Orchestrator, FortiOS SSL-VPN, Fastjson
Original source: thehackernews.com