Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw

A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild.

The vulnerability, tracked as CVE-2026-16812 (CVSS score: 10.0), is a case of operating system command injection that could pave the way for arbitrary code execution.

“VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

From brain waves to words: a new path to communication without surgery

From brain waves to words: a new path to communication without surgery Source: Hacker News

Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update

Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update Cybersecurity researchers have flagged a Microsoft Teams-themed phishing campaign that employs “secure document” lures to deliver legitimate remote monitoring

Show HN: Mail Memories – A desktop app to rescue photos from Gmail

Show HN: Mail Memories – A desktop app to rescue photos from Gmail Source: Hacker News