Arista has closed a critical security hole in its on-premises VeloCloud Orchestrator that was being actively exploited by attackers. The vulnerability, rated maximum severity, allows unauthenticated command injection on affected systems.
What happened
On Monday, Arista issued a patch for the flaw, which affects only on-premises deployments of VeloCloud Orchestrator. The company confirmed that the vulnerability was already under attack before the fix was released. No details about the attackers, targets, or scale of exploitation have been disclosed.
The patch is available immediately; Arista has not specified whether automatic updates are being pushed or if manual intervention is required. Customers running cloud-hosted instances are not impacted.
What we don’t know yet
Sources do not clarify how long the vulnerability was exposed before discovery, whether any data breaches occurred, or which specific versions of the orchestrator are vulnerable. Arista has not released indicators of compromise or detection guidance for operators who may have been targeted.
Companies mentioned
Automated pipeline · Security
Synthesized from 1 industry feed on 28 Jul 2026. Passed independent editor verification (score 85/100) before publication. Style guide v1.4.
Sources
Decision trail
- Checking for duplicates — Deduped batch of 1 candidates
- Checking for duplicates — Failed no verdict returned
- Checking for duplicates — Deduped batch of 2 candidates
- Checking for duplicates — New story No prior coverage of Arista VeloCloud Orchestrator zero-day
- Writing the article — Brief only thin sources; quick-read mode
- Writing the article — Draft created article_id=366 slug=arista-fixes-exploited-velocloud-orchestrator-zero-day quick_read=1
-
Editor review — Approved
- Score: 85/100
- Factual grounding: The draft states the patch was issued 'On Monday' (27 July 2026), but the source only confirms the publication date (27 July 2026) and does not explicitly state the patch was issued on that calendar date. The event date should be omitted or clarified as 'recently' if the exact date is not confirmed in the source.
- Style compliance: The standfirst uses 'Critical' (title case), which violates the style guide's preference for sentence case in standfirsts. Should be 'critical command-injection flaw...'.
- Audience relevance and notability: The draft does not explicitly state the CVE identifier or CVSS score, which are critical for professionals assessing the severity and tracking the vulnerability. While the source does not provide these, their absence should be noted as a gap in actionable details.
- Generating reader Q&A — Generated 3 items
- Assigning hero image — Reused library image reused image #15
- Linking related stories — Linked 5 relations from 310 candidates
- Publishing — Published arista-fixes-exploited-velocloud-orchestrator-zero-day
- Mastodon — Posted https://mstdn.social/@hostingpaper/116994865992900503



Discussion · coming soon
Be the first to join the thread when community discussion launches.