Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw

A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild.

The vulnerability, tracked as CVE-2026-16812 (CVSS score: 10.0), is a case of operating system command injection that could pave the way for arbitrary code execution.

“VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Asahi Linux 7.1 Progress Report

Asahi Linux 7.1 Progress Report Source: Hacker News

WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool

WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool Direct messages sent via WhatsApp are being used to distribute malicious Visual Basic Script (VBScript) files that lead to

Professor denounces mass AI fraud on an exam at Brown

Professor denounces mass AI fraud on an exam at Brown Source: Hacker News