Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock
What happened
Arista disclosed a critical, unauthenticated OS command‑injection in VeloCloud Orchestrator (CVE-2026-16812) that is being actively exploited and was added to the KEV list. The on‑prem orchestrator is exposed by default and Arista advises restricting the web interface to trusted management networks until fixes are applied. Operationally this creates immediate patch and isolation work for buyers that run self‑hosted SD‑WAN orchestration; watch for supplier emergency SLA demands and rapid exploit telemetry updates
Why the category manager should care
Isolate or patch on‑prem orchestrators and verify vendor emergency support and liability positions; treat this as an operational priority
Key facts
- Unauthenticated OS command‑injection vulnerability (CVE-2026-16812)
- KEV listing with evidence of active exploitation
- Vendor guidance to restrict management‑interface access until patched