TL;DR

what: Arista disclosed CVE-2026-16812, a CVSS 10.0 OS command injection in on-premises VeloCloud Orchestrator that is already being exploited in the wild.

impact: Successful exploitation gives a remote attacker privileged internal functionality on the VCO host and can extend to the VeloCloud Edge devices the orchestrator manages.

fix: Upgrade to VCO 5.2.3.14, 6.1.3.4, 6.4.2.4, or 7.0.0.1 and block the three IoC addresses 8.19.75.217, 206.72.242.124, and 206.72.242.162 if patching has to wait.

who: Any organization running self-hosted on-prem VCO; Arista-hosted and dedicated instances were fixed in advance, and FCEB agencies face a July 30, 2026 KEV deadline.