CVE-2026-16812: Arista VeloCloud Orchestrator's Actively Exploited Command Injection Zero-Day

Technical breakdown of the actively exploited pre-auth command injection zero-day in Arista VeloCloud SD-WAN Orchestrator.

CVE-2026-16812: Arista VeloCloud Orchestrator's Actively Exploited Command Injection Zero-Day
Photo by Jordan Harrison / Unsplash
📌
Security Roundup Series: Week of July 31, 2026 • 5 min read deep dive

Threat actors actively exploited a pre-authentication command injection zero-day in Arista VeloCloud SD-WAN Orchestrator, enabling remote attackers to hijack software-defined enterprise WAN deployments.

🚨
Vulnerability Intelligence: CVE ID: CVE-2026-16812 (CWE-78: OS Command Injection) Severity: Critical 9.8 (Zero-Day In-The-Wild) Target: Arista / VMware VeloCloud SD-WAN Orchestrator portal

What's Affected

Arista VeloCloud Orchestrator portals exposed to the public internet without IP allowlisting.

Remediation

✅
Action: Apply Arista's hotfix update and isolate SD-WAN orchestrator portals behind enterprise VPN or zero-trust access brokers.

Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther