CVE-2026-16812CISA KEVEPSS p61.6%

CVE-2026-16812Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability

Arista / VeloCloud Orchestrator

Description

Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.

Scoring

CVSS 10.0 ()
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS1.00% probability of exploitation · percentile 61.6% · 2026-10-05T12:00:23Z
Last modified2026-07-28

CISA KEV entry

Added to KEV: 2026-07-27

Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.