Arista VeloCloud Orchestrator OS command injection being exploited in the wild
Source headline: Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day
Intelligence Summary
SecurityWeek reports that a critical OS command injection flaw in Arista VeloCloud Orchestrator is being exploited as a zero-day. The issue affects on-premises deployments and can allow attackers to reach privileged internal functionality. Successful exploitation may enable command execution in the orchestration environment. This increases the risk of unauthorized access, further compromise, and potential disruption of managed infrastructure. Organizations using affected VeloCloud Orchestrator instances should review exposure, apply mitigations, and monitor for suspicious orchestration activity.
Recommended Action
Prioritize immediate review, validate exposure, and patch or mitigate affected systems.