NCSC-2026-0281 [1.00] [M/H] Vulnerabilities patched in Arista VeloCloud Orchestrator On-Prem
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Arista has patched vulnerabilities in VeloCloud Orchestrator On-Prem. The vulnerabilities are located in the on-premises deployment of VeloCloud Orchestrator. There is an unauthenticated endpoint that allows rotating the certificate authority. Additionally, there is a bash command injection vulnerability that allows an attacker to remotely execute arbitrary OS commands. This can compromise the confidentiality, integrity and availability of the system. There is no clear indicator of compromise, but it is recommended to investigate unusual web and backend logs in case of suspected misuse, block malicious IP addresses and preserve logs. Although no public PoC code is available yet, according to Arista the vulnerability is already being actively exploited.
CSIRTS triage
- What
- Unauthenticated endpoint allows certificate authority rotation and bash command injection enables remote code execution.
- Who is affected
- On-premises deployments of VeloCloud Orchestrator are affected.
- Urgency
- Critical; actively exploited and allows unauthenticated remote code execution.
- Action
- Apply Arista's patches immediately and investigate unusual web and backend logs for signs of compromise.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch VeloCloud Orchestrator On-Prem
Get an email when a new VeloCloud Orchestrator On-Prem advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0281
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2026-16812Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 56% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-16812 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highexploited[NEW] [high] Arista VeloCloud Orchestrator: Vulnerability enables execution of arbitrary code with root privil…cert-bund
- unknownexploitedArista Networks security advisory (AV26-751)cccs
- criticalexploitedCVE-2026-16812: VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote …nvd
- highexploitedCISA Adds Two Known Exploited Vulnerabilities to Catalogcisa
- criticalexploitedCVE-2026-16812: Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerabilitycisa-kev
Recent advisories for Arista VeloCloud Orchestrator
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highexploited[NEW] [high] Arista VeloCloud Orchestrator: Vulnerability enables execution of arbitrary code with root privil…cert-bund · 2026-08-07
- criticalexploitedCVE-2026-16812: Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerabilitycisa-kev · 2026-07-27
More from NCSC-NL Advisories
- unknownNCSC-2026-0303 [1.01] [M/H] Vulnerabilities patched in GitLab by GitLab Inc.2026-08-25
- unknownNCSC-2026-0326 [1.00] [M/H] Vulnerabilities patched in Keycloak2026-08-25
- unknownNCSC-2026-0325 [1.00] [M/H] Vulnerabilities patched in Atlassian products2026-08-24
- unknownNCSC-2026-0324 [1.00] [M/H] Vulnerability fixed in Zimbra Collaboration Suite2026-08-23
- unknownNCSC-2026-0323 [1.00] [M/H] Vulnerabilities fixed in Cisco Secure Workload2026-08-21