Arista VeloCloud Orchestrator에서 치명적인 보안 취약점이 발견되어 악용되고 있다.
Arista VeloCloud Orchestrator의 온프레미스 버전에서 명령어 주입 취약점(CVE-2026-16812)이 발견되었으며, 이는 임의 코드 실행을 초래할 수 있다. 이 취약점은 CVSS 점수 10.0으로 매우 심각한 것으로 분류된다. 현재 이 취약점은 실제 공격에 사용되고 있는 상황이다.
A critical security flaw in Arista VeloCloud Orchestrator is being actively exploited.
A command injection vulnerability (CVE-2026-16812) has been identified in the on-premises version of Arista VeloCloud Orchestrator, potentially allowing arbitrary code execution. This flaw has a CVSS score of 10.0, indicating severe risk. It is currently under active exploitation in the wild.