Skip to content
You can now search across every topic, entity and event.What's new
Arista Networks
Organisation

Arista Networks

US data-centre networking vendor; maker of the EOS switch operating system.

Arista Networks is a US data-centre networking vendor whose VeloCloud Orchestrator carried CVE-2026-16812, added to CISA's KEV catalogue on 27 July 2026 with a 30 July deadline.

Last refreshed: 3 August 2026 · Appears in 1 active topic

Timeline for Arista Networks

#12 28 Jul

Mentioned in: KEV patch clocks fell to three days

Cybersecurity: Threats and Defences
#12 28 Jul

Arista, Fortinet and Cisco flaws listed

Cybersecurity: Threats and Defences
#8 10 Jun

CISA tears up its KEV deadline rules

Cybersecurity: Threats and Defences
View full timeline →

Background

Arista Networks is a US data-centre networking vendor best known for its EOS switch operating system, widely deployed in large enterprise and cloud data centres. Arista expanded into software-defined wide-area networking through its acquisition of VeloCloud from Broadcom, which is why VeloCloud Orchestrator now appears under Arista's name in vulnerability catalogues rather than as a standalone product.

Arista EOS, the switch operating system, is tracked as a separate entity and should not be conflated with the parent company or with VeloCloud.

Arista's core customer base sits in large-scale cloud and enterprise data centres, where EOS competes with offerings from vendors such as Cisco and Juniper. The VeloCloud acquisition extended that footprint into software-defined wide-area networking, broadening Arista's exposure to a different class of deployment and a different vulnerability surface than its traditional switch business.

Key Issues
VeloCloud flaw

Arista drew a three-day patch order

CISA added CVE-2026-16812, a command injection in VeloCloud Orchestrator, to its KEV catalogue on 27 July 2026 with a 30 July Deadline, one of three flaws listed in that batch alongside entries from Fortinet and Cisco. VeloCloud Orchestrator sits in Arista's portfolio because Arista acquired VeloCloud from Broadcom; the catalogue entry reflects that ownership rather than a flaw in Arista's own EOS switch line.

The three-day window follows the pattern set on 10 June 2026, when CISA tore up its fixed 14-day default under BOD 26-04 for a four-tier model assigning 3-day, 14-day, 60-day or next-cycle deadlines depending on assessed danger.

Common Questions
Who owns VeloCloud Orchestrator?
Arista Networks, which acquired the VeloCloud SD-WAN business from Broadcom; that history is why VeloCloud entries appear under Arista's name in CISA's vulnerability catalogue.Source: CISA KEV catalogue
Why was Arista Networks added to CISA's known exploited vulnerabilities catalogue?
CISA added its VeloCloud Orchestrator On-Prem product on 27 July 2026 over an operating-system command-injection flaw, CVE-2026-16812, with a three-day federal remediation Deadline.Source: CISA KEV catalogue
What does Arista Networks make?
Data-centre networking hardware and the EOS switch operating system, plus the VeloCloud SD-WAN product line it acquired from Broadcom.Source: CISA KEV catalogue