A critical command-injection flaw in Arista VeloCloud Orchestrator shows why the software that steers networks can be as sensitive as the networks themselves.
CVE-2026-16812 puts an on-premises SD-WAN management plane under pressure, where a single command injection bug could become a wide operational problem.
Arista’s fix for an actively exploited command injection flaw in on-premises VeloCloud Orchestrator deployments is a reminder that management interfaces can be the most dangerous part of the network.