peter bassill · operator
$ cve CVE-2026-16812 JSON

CVE-2026-16812 KEV

10.0
CRITICAL · CVSS 3.1 · EPSS 1% (pctl 61)

Patch first

On CISA KEV — known exploited in the wild, due 2026-07-30.

Description

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. This functionality was intended to be for internal use only and is not intended to be remotely accessible. Hosted and Dedicated versions of VCO have already been patched in advance of this notice going out. This issue was discovered externally and is known to be actively exploited.

Scoring

CVSS10.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS1% — more likely to be exploited than 61% of all CVEs
WeaknessCWE-78
On CISA KEVyes — remediate by 2026-07-30
Public exploitnone known
Published2026-07-27
Last modified2026-07-28

CISA KEV

NameArista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability
Added2026-07-27
Due2026-07-30
Vendor / productArista / VeloCloud Orchestrator
Ransomware usenone reported

Affected (1)

VendorProduct
aristavelocloud orchestrator

References

→ the Explorer  ·  watch your stack  ·  NVD