Vulnerabilities · 48 days ago

Arista VeloCloud Patch Reaches a Trust Anchor

NCSC says Arista has patched VeloCloud Orchestrator On-Prem flaws, including an unauthenticated endpoint that can rotate the certificate authority and a remote bash command injection tracked as CVE-2026-16812. Arista says the issue is already being actively exploited.

The certificate-rotation bug matters because it can change what the appliance trusts: if an attacker can rewrite the CA, attacker-made certificates can look legitimate inside the system. That turns a management-plane break into a trust-anchor break, while the command injection gives remote OS-command execution on the box itself.

For operators running VeloCloud On-Prem, the exposure is not just the login surface but the certificate and admin state the platform controls. With no clean indicator of compromise, a foothold can be harder to spot and may outlast the obvious exploit path if the trust state was altered.

CVE-2026-16812

NVD KEV

Known exploited · CISA KEV

CVSS 10 CRITICAL: veloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host.

CISA federal remediation date Jul 30 · date passed

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-08-12

Editions

Related stories