Skip to main content
CyberConfirmedHighDevelopingFeatured
8.7

Active exploitation of critical command injection vulnerability in Arista VeloCloud Orchestrator

Threat actors are actively exploiting a CVSS 10.0 command injection vulnerability in on-premises Arista VeloCloud Orchestrator instances. The flaw allows unauthorized remote code execution, potentially granting attackers control over downstream managed Edge devices. CISA has mandated federal agencies to apply patches by July 30, 2026.

The Hacker Newsabout 19 hours agoUSCredibility 52%View source

Score Breakdown

Mosaic Score8.7
Confidence0.9
Significance0.8
Source credibility0.5

Intelligence Tags

Entities

country
Source

Related signals

8 found