Arista patches VeloCloud Orchestrator zero-day exploited in attacks
criticalDetails
A maximum-severity (CVSS 10.0) OS command injection vulnerability in on-premises Arista VeloCloud Orchestrator (VCO) is being actively exploited as a zero-day. The flaw allows attackers to execute arbitrary commands with privileged access, potentially leading to a complete system compromise.
Affected Systems
On-premises versions of Arista VeloCloud Orchestrator.
Potential Impact
Full compromise of the network orchestration platform, enabling attackers to control network traffic, access sensitive data, and pivot to other systems within the corporate network.
Mitigations
Immediately apply patches provided by Arista. Per the CISA KEV directive, federal agencies must patch this vulnerability by 2026-07-30. All organizations using the affected product should prioritize this action.