July 29, 2026
- Arista VeloCloud Orchestrator is under active exploitation as a zero-day. The on-prem OS command-injection flaw (CVSS 10.0, tracked as CVE-2026-16812 in vendor reporting) lets a remote attacker reach privileged internal functionality and run arbitrary code (Arista advisory, SecurityWeek) (earlier coverage). (discussion) · Vulnerabilities & Exploits
in Artifactory Zero-Days Confirmed as the Hugging Face AI Agent's Escape Route