Data Security , Threat Intelligence Arista patches critical command injection flaw in VeloCloud Orchestrator exploited in attacks July 28, 2026 Share By SC Staff (Adobe Stock) As reported by Bleeping Computer, Arista released a patch for a critical command injection vulnerability affecting on-premises VeloCloud Orchestrator (VCO) deployments. This flaw, identified as CVE-2026-16812, carries the maximum severity score of 10.0 and is reportedly being actively exploited in the wild. The unauthenticated OS command injection vulnerability allows remote attackers to execute arbitrary commands with privileged access on the VCO, potentially compromising the confidentiality, integrity, and availability of the orchestrator and its managed data. Exploitation requires only network access to the VCO web interface, without the need for any credentials. Arista has confirmed that this vulnerability is actively exploited, though details on the attackers and the timeline of attacks remain undisclosed. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-16812 to its Known Exploited Vulnerabilities catalog, mandating U.S. federal agencies to address it by July 30, 2026. Affected versions include specific releases of VCO 5.2.x, 6.1.x, 6.4.x, and 7.0.x. Arista advises customers to restrict network access to the VCO web interface and monitor for suspicious activity, including connections from known malicious IP addresses like 8.19.75.217, 206.72.242.124, and 206.72.242.162. Source: Bleeping Computer SC Staff Related Data Security Pope’s prayer app leaks 700,000 user emails SC Staff July 27, 2026 The Click To Pray app, endorsed by the Pope and used by hundreds of thousands worldwide, was leaking user names and email addresses for months. Data Security OnTrac parcel delivery company reports customer data breach SC Staff July 27, 2026 Bleeping Computer reports that the parcel delivery company OnTrac has experienced a data breach, potentially exposing customer personal details following a cyberattack on its corporate network. Data Security What Cloud, SaaS, and AI Data Security Actually Controls SC Media Editorial Intelligence, reviewed by Aparna Achanta July 24, 2026 The key is understanding where control assumptions break Related Events Cybercast Beyond the Hype: The Cybersecurity Trends CISOs are Keeping an Eye on in 2026 On-Demand Event Cybercast Beyond the data perimeter: Why next-generation DSPM is the foundation for modern data security On-Demand Event Virtual Conference Securing the Future of Finance: Strategies to Counter Modern Cyber Threats On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Backdoor Bit Botnet Brute Force Cryptanalysis Cryptographic Hash Functions Cyclic Redundancy Check (CRC) Darknet Information Warfare Reconnaissance You can skip this ad in 5 seconds