Arista has issued a patch for a critical command injection vulnerability in its on-premises VeloCloud Orchestrator deployments, which has been exploited by attackers. The maximum-severity flaw allows unauthorized parties to inject malicious commands, potentially leading to full system compromise. Active exploitation of this zero-day vulnerability means that defenders were caught off guard, with attacks occurring before a patch was available1. The vulnerability is particularly concerning given the critical role that VeloCloud Orchestrator plays in managing and orchestrating virtual networks. Arista's prompt issuance of a patch is a positive step, but the fact that the vulnerability was exploited before a fix was available highlights the challenges faced by defenders in keeping pace with emerging threats. The exploitation of this vulnerability underscores the importance of rapid patching and highlights the need for defenders to be vigilant in monitoring their systems for signs of compromise, so what matters most to practitioners is the need to apply this patch immediately to prevent potential attacks.
Arista patches VeloCloud Orchestrator zero-day exploited in attacks
⚠️ Critical Alert
Why This Matters
Zero-day exploitation means the vulnerability is being used before patches exist — defenders are already behind.
References
- BleepingComputer. (2026, July 27). Arista patches VeloCloud Orchestrator zero-day exploited in attacks. *BleepingComputer*. https://www.bleepingcomputer.com/news/security/arista-patches-velocloud-orchestrator-zero-day-exploited-in-attacks/
Original Source
BleepingComputer
Read original →