ARISTA Networks released patches for a critical OS injection vulnerability (CVE-2026-16812) in its VeloCloud Orchestrator (VCO) management platform, which has a CVSS score of 10 and is being exploited as a zero-day. The flaw allows remote attackers to access privileged functionalities without special configuration or authentication. Recommended actions for system defenders include reviewing web access logs for unusual activity and preserving logs for forensic analysis if compromise is suspected.
The US Cybersecurity and Infrastructure Security Agency (CISA) included this vulnerability in its Known Exploited Vulnerabilities catalog, urging federal agencies to patch it within three days.