Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Arista VeloCloud Orchestrator Security Flaw Actively Exploited

Arista VeloCloud Orchestrator Security Flaw Actively Exploited

Posted on July 28, 2026 By CWS

A critical security vulnerability affecting Arista VeloCloud Orchestrator (VCO) on-premises versions is being actively exploited. The flaw, identified as CVE-2026-16812 with a CVSS score of 10.0, involves an operating system command injection that can lead to arbitrary code execution.

Details of the Exploit

Arista Networks has disclosed this vulnerability, which could allow remote attackers to access sensitive internal functions, jeopardizing the security of the orchestrator and the data it manages. This issue was meant for internal use only and was not designed for remote access.

The vulnerability affects specific releases of VCO, including VCO 5.2.x before 5.2.3.14, VCO 6.1.x before 6.1.3.4, VCO 6.4.x before 6.4.2.4, and VCO 7.0.x before 7.0.0.1. While hosted and dedicated versions have been patched, Arista has not disclosed when the flaw was discovered or how many customers have been impacted.

Preventive Measures and Recommendations

Arista has provided indicators of compromise, including three IP addresses responsible for the attacks, and recommends customers block these addresses. It’s advised to examine logs for any signs of these IPs and preserve logs if a breach is suspected.

If updating to a fixed VCO release is not feasible immediately, it is recommended to restrict VCO web access to trusted networks, monitor for access from suspicious IPs, and review recent administrative activities for anomalies.

Wider Security Implications

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its Known Exploited Vulnerabilities catalog, mandating federal agencies to apply the patch by July 30, 2026. This development coincides with CISA including a medium-severity vulnerability in Fortinet FortiOS SSL-VPN in its catalog, which has also been actively exploited.

Additionally, a critical flaw in Alibaba’s Fastjson library (CVE-2026-16723) is under attack and remains unpatched. Users of affected versions are urged to enable SafeMode or switch to non-impacted builds promptly.

These vulnerabilities highlight the ongoing challenges in maintaining cybersecurity and the importance of timely patch management to protect against potential threats.

The Hacker News Tags:Alibaba Fastjson, Arista VeloCloud, CISA, command injection, CVE-2026-16812, Cybersecurity, Fortinet, network security, patch management, security vulnerability

Post navigation

Previous Post: Europol Enhances Efforts Against Teen Cybercrime Network
Next Post: CISA Alerts on Critical Fortinet FortiOS Vulnerability

Related Posts

Security Tools Alone Don’t Protect You — Control Effectiveness Does Security Tools Alone Don’t Protect You — Control Effectiveness Does The Hacker News
Iranian Hackers Deploy Cavern C2 Framework on Israel Iranian Hackers Deploy Cavern C2 Framework on Israel The Hacker News
Enterprise Security Gaps: Insights from 25 Million Alerts Enterprise Security Gaps: Insights from 25 Million Alerts The Hacker News
Chinese Hackers Target Azerbaijani Energy Firm via Microsoft Exchange Chinese Hackers Target Azerbaijani Energy Firm via Microsoft Exchange The Hacker News
PhantomEnigma Hijacks Government Sites for Malware PhantomEnigma Hijacks Government Sites for Malware The Hacker News
Malicious VSX Extension “SleepyDuck” Uses Ethereum to Keep Its Command Server Alive Malicious VSX Extension “SleepyDuck” Uses Ethereum to Keep Its Command Server Alive The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CISA Alerts on Critical Fortinet FortiOS Vulnerability
  • Arista VeloCloud Orchestrator Security Flaw Actively Exploited
  • Europol Enhances Efforts Against Teen Cybercrime Network
  • Origin Energy Data Breach Impacts 900,000 Customers
  • AI Singularity: OpenAI’s Altman on Autonomous Systems

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CISA Alerts on Critical Fortinet FortiOS Vulnerability
  • Arista VeloCloud Orchestrator Security Flaw Actively Exploited
  • Europol Enhances Efforts Against Teen Cybercrime Network
  • Origin Energy Data Breach Impacts 900,000 Customers
  • AI Singularity: OpenAI’s Altman on Autonomous Systems

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark