Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-07-28 ยท updated: 2026-07-28 ยท tags: [cve, kev, au-focus] ยท confidence: high ยท severity: critical ยท affected_sectors: [technology] ยท au_impact: true

CVE-2026-16812

Summary

A critical unauthenticated operating system command injection vulnerability in Arista Networks' VeloCloud Orchestrator (VCO) on-premises web interface.

Details

This vulnerability (tracked as CVE-2026-16812, CVSS 10.0 Critical) is an unauthenticated operating system (OS) command injection flaw in Arista Networks' VeloCloud Orchestrator (VCO) on-premises web interface. The flaw allows remote, unauthenticated attackers to execute arbitrary system code on the host server.

Exploitation and Defensive Guidance

CISA added CVE-2026-16812 to its Known Exploited Vulnerabilities (KEV) Catalog on July 27, 2026, due to active exploitation in the wild.

Australian Significance

For Australian organisations governed by APRA CPS 234 and operators of critical infrastructure under the SOCI Act, immediate verification and patch application for on-premises orchestrators is paramount to secure critical software supply chains. This flaw represents a severe threat to edge network perimeters and critical infrastructure networks across Australia.

Related Pages