28 July 2026
Reference: CVE-2026-16812
1. What is being reported?
The Arista VeloCloud Orchestrator software, used to manage network services, has a critical flaw that allows attackers to remotely run commands that should only be accessible internally. This means someone outside your organisation could take control of the system, access confidential data, or disrupt its operation.
2. What this means in plain English
If your organisation uses this software on-premises, attackers could exploit this flaw to steal information, change settings, or cause outages. This risk affects the confidentiality, integrity, and availability of your network management system and the data it handles.
3. Could this affect a small business?
Small businesses or charities using the on-premises version of Arista VeloCloud Orchestrator could be at risk. Those using hosted or dedicated cloud versions are likely already protected by patches. If you do not use this product, you are not affected.
4. What to do now
- Check if your organisation uses Arista VeloCloud Orchestrator on-premises software.
- If yes, contact your IT provider or software supplier immediately to apply the latest security updates or mitigations as recommended by Arista.
- Ensure your IT provider reviews your network exposure to the internet and follows government security guidance for patching.
- If no patch or mitigation is available, consider discontinuing use of the affected software until it is secured.
5. Ask your IT provider
Can you confirm whether our Arista VeloCloud Orchestrator on-premises installation is affected by CVE-2026-16812, and what steps are being taken to apply the necessary security updates or mitigations?
6. Bottom line
If you use Arista VeloCloud Orchestrator on-premises, act quickly to secure it against an actively exploited critical vulnerability.
Information based on CISA KEV, NVD, and reputable security news reports.