Hackers are exploiting CVE-2026-16812 in on-prem Arista VeloCloud Orchestrator, a command injection bug that may extend access to managed Edge devices

Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks.

VeloCloud Orchestrator CVE-2026-16812: Unauthenticated OS Command Injection Actively...