NCSC says Arista has patched VeloCloud Orchestrator On-Prem flaws, including an unauthenticated endpoint that can rotate the certificate authority and a remote bash command injection tracked as CVE-2026-16812. Arista says the issue is already being actively exploited.
The certificate-rotation bug matters because it can change what the appliance trusts: if an attacker can rewrite the CA, attacker-made certificates can look legitimate inside the system. That turns a management-plane break into a trust-anchor break, while the command injection gives remote OS-command execution on the box itself.
For operators running VeloCloud On-Prem, the exposure is not just the login surface but the certificate and admin state the platform controls. With no clean indicator of compromise, a foothold can be harder to spot and may outlast the obvious exploit path if the trust state was altered.