
Critical Arista VeloCloud Flaw Lets Attackers Execute OS Commands Remotely
Arista Networks has disclosed a maximum-severity vulnerability in its VeloCloud Orchestrator (VCO) on-prem platform that allows unauthenticated remote attackers to execute arbitrary OS commands, with active exploitation already confirmed in the wild. Tracked as CVE-2026-16812, the flaw carries a perfect CVSSv3.1 and CVSSv4.0 score of 10.0, reflecting its unauthenticated, network-exploitable nature and the complete compromise […]
The post Critical Arista VeloCloud Flaw Lets Attackers Execute OS Commands Remotely appeared first on Cyber Security News.