Threat Intelligence Brief
Curated summary with source attribution
Source: thehackernews.com
Threat Risk: High
Victim: Organizations using on-premises Arista VeloCloud Orchestrator
Incident: Active exploitation of a command injection vulnerability in Arista VeloCloud Orchestrator.
Impact: Remote attackers can achieve full system compromise of the orchestrator and subsequent access to managed edge devices.
Attacker: Unidentified threat actors
Analysis: Attackers are leveraging CVE-2026-16812 to execute arbitrary commands on the Arista VeloCloud Orchestrator (VCO) via an internal function exposed to the web. This allows remote actors to bypass security controls and potentially pivot to managed VeloCloud Edge devices. The flaw’s CVSS 10.0 score reflects the extreme risk to network infrastructure and managed data.
Recommendations: Update to the latest fixed VCO release immediately.; Restrict web interface access to trusted administrative networks only.; Block known malicious IPs (8.19.75.217, 206.72.242.124, 206.72.242.162) and audit logs for compromise.
Source: The Hacker News
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source