Vulnerabilities
Arista VeloCloud Orchestrator Zero-Day (CVE-2026-16812, CVSS 10.0) Under Active Exploitation
CVSS 10.0 on the on-premises SD-WAN management box — Arista has shipped fixes, active exploitation is confirmed, and CISA has put federal agencies on a short clock.