Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Arista VeloCloud Orchestrator Security Flaw Actively Exploited

Arista VeloCloud Orchestrator Security Flaw Actively Exploited

Posted on July 28, 2026 By CWS

A critical security vulnerability affecting Arista VeloCloud Orchestrator (VCO) on-premises versions is being actively exploited. The flaw, identified as CVE-2026-16812 with a CVSS score of 10.0, involves an operating system command injection that can lead to arbitrary code execution.

Details of the Exploit

Arista Networks has disclosed this vulnerability, which could allow remote attackers to access sensitive internal functions, jeopardizing the security of the orchestrator and the data it manages. This issue was meant for internal use only and was not designed for remote access.

The vulnerability affects specific releases of VCO, including VCO 5.2.x before 5.2.3.14, VCO 6.1.x before 6.1.3.4, VCO 6.4.x before 6.4.2.4, and VCO 7.0.x before 7.0.0.1. While hosted and dedicated versions have been patched, Arista has not disclosed when the flaw was discovered or how many customers have been impacted.

Preventive Measures and Recommendations

Arista has provided indicators of compromise, including three IP addresses responsible for the attacks, and recommends customers block these addresses. It’s advised to examine logs for any signs of these IPs and preserve logs if a breach is suspected.

If updating to a fixed VCO release is not feasible immediately, it is recommended to restrict VCO web access to trusted networks, monitor for access from suspicious IPs, and review recent administrative activities for anomalies.

Wider Security Implications

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its Known Exploited Vulnerabilities catalog, mandating federal agencies to apply the patch by July 30, 2026. This development coincides with CISA including a medium-severity vulnerability in Fortinet FortiOS SSL-VPN in its catalog, which has also been actively exploited.

Additionally, a critical flaw in Alibaba’s Fastjson library (CVE-2026-16723) is under attack and remains unpatched. Users of affected versions are urged to enable SafeMode or switch to non-impacted builds promptly.

These vulnerabilities highlight the ongoing challenges in maintaining cybersecurity and the importance of timely patch management to protect against potential threats.

The Hacker News Tags:Alibaba Fastjson, Arista VeloCloud, CISA, command injection, CVE-2026-16812, Cybersecurity, Fortinet, network security, patch management, security vulnerability

Post navigation

Previous Post: Europol Enhances Efforts Against Teen Cybercrime Network
Next Post: CISA Alerts on Critical Fortinet FortiOS Vulnerability

Related Posts

New Attack Exploits Grok Chat to Leak User Data New Attack Exploits Grok Chat to Leak User Data The Hacker News
New Phishing Kit Targeting US and EU Enterprises New Phishing Kit Targeting US and EU Enterprises The Hacker News
Masjesu Botnet: Global Threat to IoT Devices Masjesu Botnet: Global Threat to IoT Devices The Hacker News
Fortinet, Ivanti, and SAP Issue Urgent Patches for Authentication and Code Execution Flaws Fortinet, Ivanti, and SAP Issue Urgent Patches for Authentication and Code Execution Flaws The Hacker News
FBI Takes Down Chinese Hacking Platforms Targeting U.S. FBI Takes Down Chinese Hacking Platforms Targeting U.S. The Hacker News
Cisco Patches Actively Exploited SD-WAN Vulnerability Cisco Patches Actively Exploited SD-WAN Vulnerability The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • GitLab Urges Immediate Updates to Address Critical Security Vulnerabilities
  • Surfshark Security Breach: No User Data Compromised
  • PaperCut Issues New Security Updates for Critical Flaws
  • Microsoft Addresses Microsoft 365 Copilot Access Challenges
  • Russian Hackers Exploit AI for Malware Evasion, Says Anthropic

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • GitLab Urges Immediate Updates to Address Critical Security Vulnerabilities
  • Surfshark Security Breach: No User Data Compromised
  • PaperCut Issues New Security Updates for Critical Flaws
  • Microsoft Addresses Microsoft 365 Copilot Access Challenges
  • Russian Hackers Exploit AI for Malware Evasion, Says Anthropic

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark