ARISTA has confirmed that CVE-2026-16812, a command injection vulnerability in VeloCloud Orchestrator (VCO), is currently being exploited. This flaw allows remote attackers to execute OS commands without authentication, scoring a CVSS of 10.0. Affected versions include VCO 5.2.x, 6.1.x, 6.4.x, and 7.0.x prior to specified patches. Arista has issued patches and recommends urgent upgrading.
Two additional lower-severity vulnerabilities (CVE-2026-17191 and CVE-2026-17192) have been identified, requiring authenticated sessions but are not known to be actively exploited. Users are advised to restrict access and review logs for suspicious activity.