DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:09:16ZSOURCES: 14CRITICAL: 39
⚠ ACTIVE ALERTS
@MsftSecIntel CRITICAL — Microsoft Defender Experts tracked increased ACR Stealer activity from late April through… /// @TalosSecurity CRITICAL — Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+… /// @CrowdStrike CRITICAL — VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate… /// @MandiantThreats CRITICAL — Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums… /// @FalconFeedsio CRITICAL — Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on…
39Critical Threats
18Active CVEs
8IOCs Tracked
11New Advisories
TLP:WHITE
Disclosure not limited. This advisory may be distributed publicly through any channel.
OFFICIAL ADVISORY // CISA-KEV-2026-07-27 // PUBLISHED 2026-07-27

CISA KEV: Arista VeloCloud Orchestrator On-Prem OS Command Injection (CVE-2026-16812) — Actively Exploited Zero-Day

CVE-2026-16812 is a CVSS 10.0 unauthenticated OS command injection flaw in Arista VeloCloud Orchestrator On-Prem that allows remote attackers to access privileged internal functionality and execute arbitrary OS commands on the VCO host. Arista confirmed active exploitation and stated the on-premises orchestrator is exposed by default with no configuration capable of removing that exposure entirely. CISA added it to the KEV on July 27, 2026, with a federal remediation deadline of July 30, 2026 under BOD 26-04.

AFFECTED SYSTEM
SEVERITY
EXPLOIT
PATCH
Arista VeloCloud Orchestrator On-Prem 5.2.x prior to 5.2.3.14
CRITICAL
LIMITED
PATCHED
Arista VeloCloud Orchestrator On-Prem 6.1.x prior to 6.1.3.4
CRITICAL
LIMITED
PATCHED
Arista VeloCloud Orchestrator On-Prem 6.4.x prior to 6.4.2.4
CRITICAL
LIMITED
PATCHED
Arista VeloCloud Orchestrator On-Prem 7.0.x prior to 7.0.0.1
CRITICAL
LIMITED
PATCHED

Upgrade VeloCloud Orchestrator On-Prem to fixed versions: 5.2.3.14, 6.1.3.4, 6.4.2.4, or 7.0.0.1. Hosted and Dedicated VCO offerings were already patched prior to disclosure. Immediately isolate VCO management interfaces from direct internet exposure. No configuration-based workaround exists; patching is the only remediation.

Scan for anomalous HTTP POST/GET requests to VCO internal API endpoints from external IPs. Monitor OS command execution logs on the VCO host for unexpected shell activity. Alert on new user creation or privilege escalation events on the orchestrator. Review network logs for scanning activity targeting the VCO web interface on TCP/443.

  • https://www.arista.com/en/support/advisories-notices/security-advisory/24364-security-advisory-0144
  • https://www.cisa.gov/news-events/alerts/2026/07/27/cisa-adds-two-known-exploited-vulnerabilities-catalog
  • https://nvd.nist.gov/vuln/detail/CVE-2026-16812
SHARE BRIEF:✕ Post on Xin Share on LinkedIn