A maximum-severity security flaw impacting on-premises
versions of Arista VeloCloud Orchestrator (VCO) has come under
active exploitation in the wild. The vulnerability, tracked as
CVE-2026-16812 (CVSS score: 10.0), is a case of operating system
command injection that could pave the way for arbitrary code
execution. "VeloCloud Orchestrator (VCO) on-prem has a security
issue where this issue
Read more https://thehackernews.com/2026/07/attackers-exploit-arista-velocloud.html

