Arista issues a patch for a maximum-severity vulnerability in on-premises VeloCloud Orchestrator deployments that is being exploited in active attacks. Both outlets report the flaw is a command injection vulnerability, allowing attackers to run operating system commands through the orchestrator. The vulnerability impacts systems installed on-premises rather than cloud-hosted components.

SecurityWeek describes the issue as a critical zero-day and says the command injection can enable attackers to access privileged internal functionality. Bleeping Computer similarly reports that Arista has addressed a command injection flaw and that exploitation is already occurring in the wild.

While details of the exploitation method are not fully provided in the excerpts, the shared reporting indicates the risk is immediate because the vulnerability is under active attack and grants a high level of access through the orchestrator. Organizations running vulnerable versions are advised to apply Arista’s patch and follow vendor guidance to reduce exposure.