
Arista Networks
US data-centre networking vendor; maker of the EOS switch operating system.
Arista Networks is a US data-centre networking vendor whose VeloCloud Orchestrator carried CVE-2026-16812, added to CISA's KEV catalogue on 27 July 2026 with a 30 July deadline.
Last refreshed: 3 August 2026 · Appears in 1 active topic
Timeline for Arista Networks
Mentioned in: KEV patch clocks fell to three days
Cybersecurity: Threats and DefencesArista, Fortinet and Cisco flaws listed
Cybersecurity: Threats and DefencesCISA tears up its KEV deadline rules
Cybersecurity: Threats and DefencesBackground
Arista Networks is a US data-centre networking vendor best known for its EOS switch operating system, widely deployed in large enterprise and cloud data centres. Arista expanded into software-defined wide-area networking through its acquisition of VeloCloud from Broadcom, which is why VeloCloud Orchestrator now appears under Arista's name in vulnerability catalogues rather than as a standalone product.
Arista EOS, the switch operating system, is tracked as a separate entity and should not be conflated with the parent company or with VeloCloud.
Arista's core customer base sits in large-scale cloud and enterprise data centres, where EOS competes with offerings from vendors such as Cisco and Juniper. The VeloCloud acquisition extended that footprint into software-defined wide-area networking, broadening Arista's exposure to a different class of deployment and a different vulnerability surface than its traditional switch business.
Arista drew a three-day patch order
CISA added CVE-2026-16812, a command injection in VeloCloud Orchestrator, to its KEV catalogue on 27 July 2026 with a 30 July Deadline, one of three flaws listed in that batch alongside entries from Fortinet and Cisco. VeloCloud Orchestrator sits in Arista's portfolio because Arista acquired VeloCloud from Broadcom; the catalogue entry reflects that ownership rather than a flaw in Arista's own EOS switch line.
The three-day window follows the pattern set on 10 June 2026, when CISA tore up its fixed 14-day default under BOD 26-04 for a four-tier model assigning 3-day, 14-day, 60-day or next-cycle deadlines depending on assessed danger.