ShellCodeX Intelligence Brief
CRITICAL
Cybersecurity
Arista fixes actively exploited command injection in VeloCloud Orchestrator
Source headline: Arista patches VeloCloud Orchestrator zero-day exploited in attacks
Threat level
Critical
Signal strength
80/100
Source confidence
1 source
Published
2 hours ago
Intelligence Summary
Arista has released patches for a maximum-severity command injection flaw in on-premises VeloCloud Orchestrator deployments. The vulnerability is reported to be actively exploited in the wild, which raises the risk of remote command execution. Successful exploitation could allow attackers to run commands on affected systems. Organizations using VeloCloud Orchestrator should update to the fixed versions as soon as possible. Review exposure and consider implementing compensating controls until patching is complete.
Recommended Action
Prioritize immediate review, validate exposure, and patch or mitigate affected systems.
Topics
Original reporting
BleepingComputer
Arista patches VeloCloud Orchestrator zero-day exploited in attacks
Open original source