HOMEVULNERABILITIESCVE-2026-16812
CRITICALCISA KEVIN THE WILD

CVE-2026-16812

CWE-78Published: July 27, 2026· Updated: Jul 28, 2026

10.0
CVSS v3.1

Official Description

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.

This functionality was intended to be for internal use only and is not intended to be remotely accessible.

Hosted and Dedicated versions of VCO have already been patched in advance of this notice going out.

This issue was discovered externally and is known to be actively exploited.

NVD Source

Technical Analysis

CVE-2026-16812 can be exploited remotely over the network without requiring physical or adjacent access, significantly expanding the attack surface for threat actors.

The vulnerability requires no privileges and no user interaction, making it a prime target for automated exploitation campaigns and worm-like propagation.

A successful exploit results in complete confidentiality breach (data exposure), full integrity compromise (data manipulation), availability disruption (denial of service), with a CVSS base score of 10.0.

The vulnerability has a "Changed" scope, meaning successful exploitation can impact components beyond the vulnerable component itself — such as the host operating system or adjacent services.

CISA has added CVE-2026-16812 to the Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild. U.S. federal agencies are required to patch this within the mandated timeframe, and all organizations should treat remediation as urgent.

CVSS v3.1 Vector Breakdown

Exploitability
Attack VectorNetwork
Attack ComplexityLow
Privileges Req.None
User InteractionNone
ScopeChanged
Impact
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Exploit & PoC Resources

ACTIVE EXPLOITATIONConfirmed exploitation in the wild
External links open in a new tab. Always verify in a controlled environment before use.

News & Research Mentioning CVE-2026-16812

Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
The Hacker News· Jul 28, 2026

A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-16812 (CVSS score: 10.0), is a case of operating system command injection that could pave the way for arbitrary code execution. "VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue [xlite_meta score:50 src:The Hacker News xlite_fp:b415e0c108154eb25c6720ad8a082df6dea30fb00e81483d4adfb21fe9fec07b]

CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA Alerts· Jul 27, 2026

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-68686 Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability CVE-2026-16812 Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize [xlite_meta score:51 src:CISA Alerts xlite_fp:1d722d204cdb50a87a16c182843d87452412bec9ee02d6c3e5eafccebd2e42e9]

All References (2)

Quick Facts

CVE IDCVE-2026-16812
CVSS Score10.0 / 10
SeverityCRITICAL
WeaknessCWE-78
CISA KEVYES — Active Exploitation
ExploitIN THE WILD
PublishedJul 27, 2026

Related CVEs (CWE-78)

Recommended Actions

  • Apply vendor patches immediately
  • Monitor CVE-2026-16812 in threat intel feeds
  • Review IDS/IPS signatures for exploitation attempts
  • !CISA KEV: Federal agencies must patch per BOD 22-01 timeline
  • !Active exploitation confirmed — treat as P1
Data sourced from NVD (NIST), CISA KEV, and EPSS (FIRST). Analysis generated by CTIWatch. CVE data is provided under the NVD usage policy.