Arista patches a CVSS 10 flaw under active exploitation in VeloCloud Orchestrator
On September 22, 2026, CISA added a CVSS 10 input-validation flaw in Arista’s on-prem VeloCloud Orchestrator to its KEV catalog, exploitable with no credentials. Restrict network access to the VCO web interface and apply the fix before September 25.