CVE-2026-16812 · High · CISA KEV
Arista VeloCloud Orchestrator OS Command Injection: Critical Risk to Orchestrator Hosts
Threat Engine Auto-Feed · data current as of 2026-07-28
Arista VeloCloud Orchestrator On-Prem is vulnerable to an OS command injection, allowing remote attackers to access privileged internal functionality. This vulnerability is actively exploited in the wild, as confirmed by its inclusion in CISA's KEV catalog. Successful exploitation can severely compromise the confidentiality, integrity, and availability of the orchestrator and its managed data.
- CVSS:
- EPSS percentile: 0.58631
- Exploitation pressure: 60/100 (High)
Exploitation reality: listed in CISA KEV (exploited in the wild) · EPSS 59th percentile. Threat × Vulnerability from public signals — impact depends on your environment.
Weakness —
An OS command injection vulnerability occurs when an application constructs a system command using user-supplied input without proper validation or sanitization. This allows an attacker to inject arbitrary operating system commands, which the application then executes with the privileges of the vulnerable service. In this case, it grants access to privileged internal functions.
Who's at risk
Exposure: unknown · Auth: unknown · unknown
Enterprise profiles most at risk
- Organizations utilizing Arista VeloCloud Orchestrator On-Premises deployments
- Financial services organizations (due to assessed targeting by FIN7, LockBit affiliates, APT38)
- Technology sector organizations (due to assessed targeting by APT29, Scattered Spider)
Misconfigurations that escalate it
- Lack of network segmentation for VeloCloud Orchestrator instances
- Insufficient monitoring of VeloCloud Orchestrator logs for unusual activity
High-impact scenarios
- Complete compromise of the VeloCloud Orchestrator host, leading to unauthorized access to network configurations and managed data.
- Disruption of network services and operations managed by the orchestrator, impacting availability.
- Unauthorized disclosure or modification of sensitive data processed or stored by the orchestrator.
Likely adversaries
- FIN7 — Financial services (Assessed)
- LockBit affiliates — Financial services (Assessed)
- APT38 (Lazarus) — Financial services (Assessed)
- APT29 (Cozy Bear) — Technology (Assessed)
- Scattered Spider — Technology (Assessed)
What to do (defensive)
Detect
- Monitor VeloCloud Orchestrator logs for unusual command execution or access to privileged internal functionality.
- Implement network intrusion detection systems (NIDS) to identify suspicious traffic patterns to and from the orchestrator.
Contain
- Isolate affected VeloCloud Orchestrator instances from the broader network if compromise is suspected.
- Review and restrict network access controls to the VeloCloud Orchestrator to only necessary administrative interfaces.
Patch
- Apply vendor-provided security patches for Arista VeloCloud Orchestrator On-Prem as soon as they become available.
Frontier verdict — High
This vulnerability is critical due to active exploitation in the wild (CISA KEV) and the potential for full compromise of the orchestrator and managed data.
For detection-engineering and awareness only · point-in-time · not security advice · sourced from NVD, FIRST EPSS, CISA KEV. Adversary mappings are assessments unless cited.