boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-16812CRITICAL
Arista Networks VeloCloud Orchestrator On-Prem — VeloCloud Orchestrator OS Command Injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H   10.0   .0088   56.4   YES
AFFECTED
  Product                         Versions  Fixed
  VeloCloud Orchestrator On-Prem  5.2.0 –   —
TIMELINE
  Jul 23  Reserved by Arista
  Jul 27  Added to CISA KEV, remediation due 2026-07-30
  Jul 27  Published (CNA: Arista)
  Jul 31  DUE DATE PASSED — CVE-2026-16812 (Arista Networks VeloCloud Orchestrator On-Prem). CISA remediation deadline was July 30, 2026; still in catalog.
CWE-78 · CNA: Arista · CVSS v4.0 · 2 references · NVD status: Analyzed · KEV due July 30, 2026

Description

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. This functionality was intended to be for internal use only and is not intended to be remotely accessible. Hosted and Dedicated versions of VCO have already been patched in advance of this notice going out. This issue was discovered externally and is known to be actively exploited.

Lifecycle

Complete event history — 4 events, chronological
DateEventDetail
July 23, 2026ReservedReserved by Arista
July 27, 2026KEV ADDEDAdded to CISA KEV, remediation due 2026-07-30
July 27, 2026PublishedPublished (CNA: Arista)
July 31, 2026DUE DATE PASSEDDUE DATE PASSED — CVE-2026-16812 (Arista Networks VeloCloud Orchestrator On-Prem). CISA remediation deadline was July 30, 2026; still in catalog.

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
Arista NetworksVeloCloud Orchestrator On-Prem5.2.0

Weaknesses

CWE-78

References (2)

Related

Authoritative record: CVE-2026-16812 at cve.org

Vendors: arista networks

Weaknesses: CWE-78

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-16812 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.