Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Arista Networks VeloCloud Orchestrator On-Prem — VeloCloud Orchestrator OS Command Injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N H H H 10.0 .0088 56.4 YES
AFFECTED
Product Versions Fixed
VeloCloud Orchestrator On-Prem 5.2.0 – —
TIMELINE
Jul 23 Reserved by Arista
Jul 27 Added to CISA KEV, remediation due 2026-07-30
Jul 27 Published (CNA: Arista)
Jul 31 DUE DATE PASSED — CVE-2026-16812 (Arista Networks VeloCloud Orchestrator On-Prem). CISA remediation deadline was July 30, 2026; still in catalog.
Description
VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.
This functionality was intended to be for internal use only and is not intended to be remotely accessible.
Hosted and Dedicated versions of VCO have already been patched in advance of this notice going out.
This issue was discovered externally and is known to be actively exploited.
Lifecycle
Complete event history — 4 events, chronological
| Date | Event | Detail |
| July 23, 2026 | Reserved | Reserved by Arista |
| July 27, 2026 | KEV ADDED | Added to CISA KEV, remediation due 2026-07-30 |
| July 27, 2026 | Published | Published (CNA: Arista) |
| July 31, 2026 | DUE DATE PASSED | DUE DATE PASSED — CVE-2026-16812 (Arista Networks VeloCloud Orchestrator On-Prem). CISA remediation deadline was July 30, 2026; still in catalog. |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Arista Networks | VeloCloud Orchestrator On-Prem | — | 5.2.0 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-16812 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.