← Back

Wire · regulatory

Active Exploitation Alert: Arista VeloCloud Orchestrator CVE-2026-16812 Command ...

Published

28 July 2026

Topic

regulatory

Sectors

CybersecurityEnterprise Software

Source

Read at rescana.com

Verified

Fusion42 · 28 July 2026 · Fusion42 review

Arista VeloCloud Orchestrator contains a critical unauthenticated command injection vulnerability (CVE-2026-16812) now on the CISA Known Exploited Vulnerabilities catalog, enabling remote attackers to execute arbitrary OS commands and compromise SD-WAN infrastructure. Exploitation is actively occurring in the wild across finance, healthcare, manufacturing, and critical infrastructure sectors.

This Wire brief sits within Fusion42's coverage of Cybersecurity and Enterprise Software, and 4 sources have reported it.

◆ The Wire takeaway

Enterprise customers running Arista VeloCloud Orchestrator exposed to the internet are actively being breached right now, and attackers are using the compromised orchestrator to move sideways into branch networks and cloud. Your customer success team has 48 hours before ransomware groups working from this vulnerability reach out to your clients directly.

Coverage

4 sources · 28 Jul 2026

Related on Wire

Topics

CybersecurityEnterprise Softwarezero-daysd-wancritical-infrastructureactive-exploitationcommand-injection