CVE-2026-16812: OS Command injection in VeloCloud Orchestrator, 10.0 rating 🔥
A new vulnerability in Arista VeloCloud Orchestrator (VCO) allows an unauthenticated remote attacker run OS commands on the VCO host. A compromise can also expose managed devices. This vulnerability is already being actively exploited in the wild!
Search at Netlas.io:
👉 Link: https://nt.ls/PkM4n
👉 Dork: http.body:"single-spa-application:@velocloud/vco-header" OR http.body:"vco/branding.css" OR http.body:"vco/favicon"
Vendor's advisory:
https://www.arista.com/en/support/advisories-notices/security-advisory/24364-security-advisory-0144
Post #602
595

- ❤ 4
- 🔥 4