Wire · technology
Arista patches critical command injection flaw in VeloCloud Orchestrator exploited in attacks
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 28 July 2026 · Fusion42 review
Arista has patched CVE-2026-16812, a critical unauthenticated command injection vulnerability in VeloCloud Orchestrator that allows remote attackers to execute arbitrary privileged commands. The flaw is actively exploited in the wild and CISA has mandated US federal agencies patch by 30 July 2026.
This Wire brief sits within Fusion42's coverage of Cybersecurity. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur reasons over.
◆ ◆ The Wire takeaway
Your SD-WAN orchestration platform is now a proven attack vector and a federal procurement blocker until patched. Any customer using Arista VeloCloud on-premises needs remediation within 72 hours, and any vendor selling to US government agencies must validate their entire stack against active exploits.
◆ Related on Wire
◆ Topics