CISA has added CVE‑2026-16812 to its Known Exploited Vulnerabilities catalogue, affecting Arista’s VeloCloud Orchestrator On‑Prem product. The vulnerability is an OS command injection flaw that could let a remote attacker execute privileged commands on the orchestrator host, potentially compromising confidentiality, integrity and availability of the system and the data it manages.
Technically, CVE‑2026-16812 is an OS command injection vulnerability with a CVSS v3.1 base score of 10.0, rated CRITICAL. The attack vector is network‑based, requiring no user interaction or privileges to exploit. Successful exploitation allows arbitrary command execution on the underlying operating system. At present, no patch has been made available, and the vendor has not released a mitigating update.
Active exploitation has been confirmed, which is the basis for its inclusion in the KEV catalogue. There is no publicly known ransomware campaign linked to this vulnerability. CISA has set a remediation due date of 30 July 2026 for federal civilian executive branch (FCEB) agencies to address the issue.
CISA’s required action is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26‑04 Prioritizing Security Updates Based on Risk guidance and CISA’s “Forensics Triage Requirements”. Follow applicable BOD 26‑04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26‑04 patching guidelines.
While the directive binds FCEB agencies, all organisations should review their exposure to Arista VeloCloud Orchestrator On‑Prem and apply any available mitigations promptly.
For full details, consult the NVD entry at https://nvd.nist.gov/vuln/detail/CVE-2026-16812 and the CISA KEV catalogue.