TL;DR what: Arista disclosed CVE-2026-16812, a CVSS 10.0 OS command injection in...

Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks.

VeloCloud Orchestrator CVE-2026-16812: Unauthenticated OS Command Injection Actively...