SECURITY·중요도 9·2026. 07. 28.·The Hacker News

Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw

── KO ──────────────────

Arista VeloCloud Orchestrator에서 치명적인 보안 취약점이 발견되어 악용되고 있다.

Arista VeloCloud Orchestrator의 온프레미스 버전에서 명령어 주입 취약점(CVE-2026-16812)이 발견되었으며, 이는 임의 코드 실행을 초래할 수 있다. 이 취약점은 CVSS 점수 10.0으로 매우 심각한 것으로 분류된다. 현재 이 취약점은 실제 공격에 사용되고 있는 상황이다.


── EN ──────────────────

A critical security flaw in Arista VeloCloud Orchestrator is being actively exploited.

A command injection vulnerability (CVE-2026-16812) has been identified in the on-premises version of Arista VeloCloud Orchestrator, potentially allowing arbitrary code execution. This flaw has a CVSS score of 10.0, indicating severe risk. It is currently under active exploitation in the wild.

원문 보기 →목록으로