Wire · technology
Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 28 July 2026 · Fusion42 review
A maximum-severity command injection vulnerability (CVE-2026-16812, CVSS 10.0) in Arista VeloCloud Orchestrator on-premises versions is under active exploitation, allowing remote attackers arbitrary code execution and full compromise of the orchestrator and its managed data.
This Wire brief sits within Fusion42's coverage of Telecom & Connectivity, and 4 sources have reported it.
◆ ◆ The Wire takeaway
Network orchestration infrastructure just became an active attack vector. Every enterprise running unpatched Arista VeloCloud on-prem is compromised right now, and incident response, forensics, and patching services are about to spike; if you build security or remediation tooling for network layers, customers will call this week.
◆ Coverage
4 sources · 28 Jul 2026
◆ Related on Wire
◆ Topics