- A maximum-severity command injection flaw (CVE-2026-16812, CVSS 10.0) in on-premises Arista VeloCloud Orchestrator (VCO) is under active exploitation.
- CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog, requiring federal agencies to patch by July 30, 2026.
- Additional vulnerabilities under active attack include a Fortinet FortiOS SSL-VPN flaw (CVE-2025-68686) and an unpatched critical issue in Alibaba’s Fastjson library (CVE-2026-16723).
A critical remote code execution vulnerability in on-premises versions of Arista VeloCloud Orchestrator (VCO) is being actively exploited in the wild as of July 28, 2026. Tracked as CVE-2026-16812 and holding the maximum CVSS score of 10.0, the operating system command injection flaw allows a remote attacker to access privileged internal functionality. Arista stated that successful exploitation could compromise the orchestrator’s confidentiality, integrity, and availability.
The issue was already addressed in hosted and dedicated VCO versions, but multiple on-premises releases remain vulnerable, including all versions of VCO 5.2.x prior to 5.2.3.14. While Arista acknowledged the flaw was externally discovered and actively exploited, it did not disclose how many customers were impacted. As indicators of compromise, the company shared three IP addresses linked to the attacks: 8.19.75.217, 206.72.242.124, and 206.72.242.162.
Arista warned that compromises to the VCO platform could grant attackers access to VeloCloud Edge devices as well. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the flaw to its Known Exploited Vulnerabilities catalog, requiring Federal Civilian Executive Branch agencies to apply patches by July 30, 2026.
Meanwhile, CISA also added a medium-severity vulnerability in Fortinet FortiOS SSL-VPN (CVE-2025-68686, CVSS 5.3) to its catalog, citing active exploitation evidence. Fortinet said an attacker would first need to compromise the product via another vulnerability, with federal agencies given until August 10, 2026, to patch.
Another security flaw under attack is CVE-2026-16723 (CVSS 9.0), a critical unpatched issue in Alibaba’s Fastjson library that enables remote code execution. Developers using versions 1.2.68 through 1.2.83 are urged to enable SafeMode or switch to a non-impacted build immediately.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
