<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — Arista</title><description>Actively exploited vulnerabilities affecting Arista products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/arista.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-16812 — Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-16812</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-16812</guid><description>This vulnerability in Arista VeloCloud Orchestrator allows a remote attacker to inject operating system commands, potentially gaining access to privileged internal functions of the orchestrator. Because VeloCloud Orchestrator manages and coordinates SD-WAN infrastructure, a successful attack could compromise the confidentiality, integrity, and availability of both the orchestrator itself and all the network data and configurations it manages — making this a high-impact target for attackers.</description><pubDate>Mon, 27 Jul 2026 00:00:00 GMT</pubDate><category>Arista</category><category>VeloCloud Orchestrator</category></item><item><title>CVE-2026-7473 — Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-7473</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-7473</guid><description>Arista EOS switches with tunnel decapsulation configured can incorrectly decapsulate and forward unexpected tunneled packets whose destination IP matches the switch&apos;s decapsulation IP. This means an attacker could craft malicious tunneled traffic that the switch processes and forwards when it should not, potentially bypassing network segmentation or security controls. Any environment running affected Arista EOS versions with tunnel decapsulation enabled is at risk of unintended packet forwarding.</description><pubDate>Tue, 09 Jun 2026 00:00:00 GMT</pubDate><category>Arista</category><category>Extensible Operating System</category></item></channel></rss>