DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:09:16ZSOURCES: 14CRITICAL: 39
⚠ ACTIVE ALERTS
@MsftSecIntel CRITICAL — Microsoft Defender Experts tracked increased ACR Stealer activity from late April through… /// @TalosSecurity CRITICAL — Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+… /// @CrowdStrike CRITICAL — VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate… /// @MandiantThreats CRITICAL — Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums… /// @FalconFeedsio CRITICAL — Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on…
39Critical Threats
18Active CVEs
8IOCs Tracked
11New Advisories
TLP:WHITE
Disclosure not limited. This advisory may be distributed publicly through any channel.
OFFICIAL ADVISORY // CISA-KEV-2026-07-27 / Arista SA CVE-2026-16812 // PUBLISHED 2026-07-27
CISA KEV / Arista PSIRTCVE-2026-16812

Arista VeloCloud Orchestrator On-Prem — CVSS 10.0 Unauthenticated OS Command Injection (CVE-2026-16812)

A maximum-severity (CVSS 10.0) unauthenticated OS command injection flaw in Arista VeloCloud Orchestrator On-Prem allows remote attackers to reach privileged internal functionality, execute arbitrary commands, and fully compromise the orchestrator host and all managed SD-WAN edge devices. Active exploitation was confirmed by Arista and CISA added it to the KEV catalog on July 27, 2026 with a federal FCEB remediation deadline of July 30. Hosted and dedicated VCO versions were patched ahead of the disclosure; only on-premises deployments require customer action.

AFFECTED SYSTEM
SEVERITY
EXPLOIT
PATCH
Arista VeloCloud Orchestrator (VCO) On-Prem — all versions prior to vendor-supplied fix
CRITICAL
LIMITED
PATCHED

Apply the vendor-supplied VCO On-Prem patch immediately per Arista's security advisory. After patching, perform credential rotation for all administrator accounts on the orchestrator. Validate the state of all managed VeloCloud Edge devices and restore or replace affected orchestrator instances from trusted backups if compromise is suspected. Restrict VCO management interface exposure to the internet; place behind VPN or network access control where operationally feasible.

Scan for internet-exposed VCO management endpoints (default ports). Review VCO HTTP access logs for anomalous POST/GET requests to privileged internal API paths. Investigate any unexpected command execution events or new scheduled jobs on the orchestrator host. Audit administrator activity logs within VCO for unauthorized configuration changes to managed edge devices.

  • https://www.arista.com/en/support/advisories-notices/security-advisories/
  • https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  • https://thehackernews.com/2026/07/attackers-exploit-arista-velocloud.html
  • https://nvd.nist.gov/vuln/detail/CVE-2026-16812
SHARE BRIEF:✕ Post on Xin Share on LinkedIn