Arista has patched an actively exploited VeloCloud Orchestrator zero-day that could allow remote attackers to take control of affected on-premises systems. The vulnerability, tracked as CVE-2026-16812, is an unauthenticated operating system command injection flaw with a maximum CVSS severity score of 10.0. It affects on-premises VeloCloud Orchestrator, also known as VCO. The platform centrally configures,…