Cyber Resilience
← All news

KEV: CVE-2026-16812 — Arista VeloCloud Orchestrator (Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability)

Our takeCISA added CVE-2026-16812 to KEV: unauthenticated OS command injection in on-prem Arista VeloCloud Orchestrator, actively exploited. Patch VCO now if you self-host it; managed/cloud SD-WAN tenants can skip this one.
Sources (3)
What this means for you — Security leader:If you run Arista VeloCloud Orchestrator on-prem, treat CVE-2026-16812 as urgent: unauthenticated OS command injection, actively exploited, and now in KEV. Patch per Arista’s guidance and check the orchestrator host and managed Edge devices for compromise.
What this means for you — Lean IT orgs:This only matters if you run Arista VeloCloud Orchestrator on-premises yourself—most lean-IT shops do not. If a provider manages your SD-WAN, ask them whether you are affected and whether they have patched.
What this means for you — MSP:Inventory clients with on-prem Arista VeloCloud Orchestrator; this is unauthenticated command injection under active exploitation with a KEV deadline. Patch immediately and review orchestrator hosts and managed Edges for signs of compromise.
What this means for you — Researcher:KEV add for a max-severity unauthenticated OS command injection in on-prem VeloCloud Orchestrator under active exploitation. Review Arista’s advisory for affected branches and the privileged internal functionality reachable from the VCO attack surface.